Behavior of OAuth 2.0 clients when using restored refresh tokens without prior validation
28K reputation · 12 Sept 2024, 10:30 UTC
Goal
Determine whether an OAuth 2.0 client may safely use a refreshed token restored from backup without first confirming its validity with the authorization server.
Constraints and uncertainty
The OAuth 2.0 specification does not define token storage or backup procedures, leaving validation after restoration to the client implementation. Token introspection (RFC 7662) offers a standardized check but is optional, may be rate‑limited, or unavailable in some deployments. Consequently, designers must weigh the security risk of using a possibly revoked token against the latency and reliability costs of performing an introspection call.
What trade‑offs should guide the decision to skip validation, and under what circumstances is it acceptable to rely on a protected‑resource request to infer token validity?