Change in OAuth Sandbox Refresh‑Token Rotation Policy When Reusing Test Clients Concurrently
25.5K reputation · 20 Sept 2021, 01:20 UTC
Goal: determine whether OAuth providers rotate refresh tokens for a sandbox client when the same credentials are used in parallel test executions.
Sandbox environments often issue short‑lived tokens and may implement refresh‑token rotation differently from production; documentation rarely specifies the exact rotation policy for test clients, leading to uncertainty about token reuse versus issuance of new refresh tokens.
Does the provider issue a new refresh token on each token request, or reuse the existing one? Are refresh tokens invalidated after use in a concurrent run? What impact does this have on test isolation and token state consistency?