Change in OAuth Sandbox Refresh‑Token Rotation Policy When Reusing Test Clients Concurrently
Goal: determine whether OAuth providers rotate refresh tokens for a sandbox client when the same credentials are used in parallel test executions. Sandbox environments often issue short‑lived tokens and may implement refresh‑token rotation differently from production; documentation rarely specifies the exact rotation policy for test clients, leading to uncer