I’d like to second this. The “workaround” detailed here requires the implementing client to be concerned with the validity or invalidity of the key, which is something that I never want to have to think about in application code. It seems to imply application-level dynamic key management, which not every company will have implemented, nor will have engineering time to implement.
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| API Services - machine-to-machine authentication - multiple client secrets needed | 1 | 1037 | November 14, 2023 | |
| How to handle Enterprise connection client secret expiration? | 1 | 860 | May 7, 2024 | |
| Client Secret Rotation for M2M Applications in Auth0 | 1 | 268 | December 17, 2024 | |
| Provisioning credentials per-client | 3 | 68 | September 4, 2026 | |
| Retrieve non rotating refresh token using SPA sdk | 4 | 1951 | August 26, 2022 |