- Will no longer be returned when using the implicit grant for authentication.
- Can be used by confidential applications.
- Can be used with Refresh Token Rotation by public applications when using the Authorization Code Flow with PKCE.
- Should use the
/oauth/tokenendpoint to get new tokens because the/delegationendpoint is deprecated.
Legacy (delegation)
OIDC-conformant (token endpoint)
audienceandclient_secretparameters are optional.client_secretis not needed when requesting arefresh_tokenfor a public application.
Refresh Tokens must be kept confidential in transit and storage, and they should be shared only among the authorization server and the client to whom the refresh tokens were issued.