What is the purpose of a “Refresh Token”?

后端 未结 4 1133
伪装坚强ぢ
伪装坚强ぢ 2020-12-02 09:01

I have a program that integrates with the YouTube Live Streaming API. It runs on timers, so its been relatively easy for me to program in to fetch a new Access Token every 5

4条回答
  •  旧时难觅i
    2020-12-02 09:46

    @Teyam mention SO post Why Does OAuth v2 Have Both Access and Refresh Tokens? but I prefer the another answer there: https://stackoverflow.com/a/12885823/254109

    TL;DR refresh_token does not bring increased security. It's for the purpose to improve scalability and performance. Then, access_token may be stored just in some fast, temporary storage (like memory). It allows the authorization and resource server separation, too.

提交回复
热议问题