Improved
Changes to OAuth2 Refresh Tokens
over 2 years ago by Spendesk API team
Breaking ChangesThe OAuth2 Refresh Token
POSTendpoint now supports two new mandatory query parameters:
client_id- The original Client ID received by Spendeskclient_secret- The original Client Secret received by SpendeskThese two new parameters are needed for us to successfully rotate your access and refresh tokens in a more secure fashion. Without them, the request will result in a response with the status code
400.In addition to the breaking changes announced above, the OAuth2 Refresh Token
POSTendpoint also now returns a new property:
refresh_token- The new refresh token to be used from then on outThis new refresh token will invalidate the previously returned one in the OAuth2 Access Token
POSTendpoint, and has a validation period 30 days.