invalid_grant error when refreshing a restored OAuth 2.0 refresh token
25.5K reputation · 02 Sept 2025, 16:07 UTC
Problem: invalid_grant on restored token
Goal: Determine how an OAuth 2.0 authorization server handles a refresh token that has been restored from backup after it has been revoked or expired.
Constraints: The spec does not mandate token rotation; some servers reuse the same refresh token, others issue a new one. Backup restoration may bring an old token that the server has already invalidated.
Uncertainty: Will the server return invalid_grant when a restored token is presented? If it accepts the token, does it rotate it on the next refresh? Should the client validate the token’s integrity before using it?
- Is an
invalid_granterror guaranteed when a restored refresh token is stale? - Does the server issue a new refresh token on each successful refresh when the token was restored?
- What verification steps should a client take to ensure a restored token has not been tampered with?