Sign In with LinkedIn granular OAuth scopes: legacy token access after refresh or re-authentication is undefined
0 reputation · 31 Mar 2022, 09:55 UTC
Sign In with LinkedIn's current product issues granular OpenID Connect scopes such as openid, profile, and email, replacing legacy broad scopes like r_basicprofile that returned most member fields under a single grant. Migrating an existing integration means requesting each permission explicitly and collecting member consent per data class.
The unresolved part is what happens to integrations that still hold legacy grants. LinkedIn has not announced a fixed sunset date for grandfathered apps, and enforcement may vary by app tier, verification status, and region. It is therefore unclear whether a routine token refresh preserves the originally granted field access, or whether the next re-authentication narrows the grant to the current scope set. With no repeatable end-to-end development environment for these flows, behavior has to be confirmed through sandbox apps and a limited set of test members.
- Does refreshing a legacy-scoped token continue to return the originally granted profile fields, or does it require fresh consent under the granular scopes?
- When a member re-authenticates, which scope set governs the new grant, and can an application detect a narrowed scope at runtime before profile-dependent features fail?