OAuth Implicit Grant Deprecation: Transitioning to Authorization Code with PKCE
0 reputation · 25 Sept 2021, 12:47 UTC
The goal is to maintain the ability to revert a client’s configuration from the authorization code flow with PKCE back to the deprecated implicit grant after a failed upgrade, while preserving existing sessions and tokens.
Constraints include the absence of a defined deprecation window for the implicit grant in OAuth 2.0/2.1, the need to keep both grant types registered simultaneously, and the risk that refresh‑token rotation with reuse detection may invalidate an entire token family if an older client replays a rotated token. Additionally, token format changes (opaque vs. JWT access tokens) are only reversible if resource servers accept both formats during the transition.
What overlap period and monitoring criteria should be used before disabling the implicit grant? How can resource servers be configured to accept both opaque and JWT access tokens during the transition to allow rollback?