# Refresh Token Validity

**URL:** <https://devforum.zoom.us/t/refresh-token-validity/12093>\
**Category:** App Marketplace\
**Created:** [April 8, 2020, 9:52am UTC](https://devforum.zoom.us/t/refresh-token-validity/12093 "2020-04-08T09:52:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![hedaoo.abhishek1993](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/hedaoo.abhishek1993/32/5296_2.png) [@hedaoo.abhishek1993](https://devforum.zoom.us/u/hedaoo.abhishek1993)\
**Post date:** [April 8, 2020, 9:52am UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/1 "2020-04-08T09:52:23Z")

</div>

Refresh token has 15 years validity, yet it is only one time use. Once we generate the access token using the refresh token, it gets invalidated. Any way where I can reuse it again? (I am aware that we get new refresh token when we generate access token).

**Which App?**  
OAuth application

**Additional context**  
Issue is in multi threaded environment, if the access token is generated by one thread(which generates new refresh token), refresh token on the other thread is invalidated. This breaks the application. (We cannot share the refresh token between threads or read it from common location).

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 8, 2020, 5:00pm UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/2 "2020-04-08T17:00:49Z")

</div>

Hey @hedaoo.abhishek1993,

Checkout these threads:

> [@How to protect against losing refresh\_token response](https://devforum.zoom.us/t/how-to-protect-against-losing-refresh-token-response/10375):
>
> Description refresh\_token may be lost by the network Error The Zoom OAuth2 documentation [https://marketplace.zoom.us/docs/guides/auth/oauth#refreshing](https://marketplace.zoom.us/docs/guides/auth/oauth#refreshing) says “The latest refresh token must always be used for the next refresh request.” This way, if we make a request to get a new access token, and the request is successfully received by Zoom, and new tokens are issued, but on the way back there is a network failure, we would lose the new refresh token and the integration would no longer functio…

> [@How to refresh token if refresh\_token in incorrect](https://devforum.zoom.us/t/how-to-refresh-token-if-refresh-token-in-incorrect/3338/19):
>
> Actually, it has happened again. And this time, I got to the diagnostic logs early enough to see why. Here is what happened: Client (my) code sends request with good OAuth refresh token, client ID and client secret to the Zoom OAuth server. Zoom OAuth server appears to have processed the request successfully, and is sending a response back with the new OAuth token. But, my client code got a gateway timeout exception reading the response. So, I never got the new OAuth token and thus now only…

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![katyle](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/katyle/32/1098_2.png) [@katyle](https://devforum.zoom.us/u/katyle)\
**Post date:** [April 9, 2020, 1:05am UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/3 "2020-04-09T01:05:07Z")

</div>

Hi Tommy.

So, I would like to formally request that “token expiry tolerance” be increased for our PowerSuite Zoom application. Note that this application is multi-tenant account-level OAuth. And, it is a background service. The end user has 0  
interaction with the Zoom application (other than doing the first-time authorization of our application to retrieve their Zoom data). We can’t go ask the end-user administrator to go re-authorized our Zoom application because their Zoom access token is now  
invalid due to a rare (but has happened) connectivity error receiving the response from the Zoom OAuth server from a token refresh request. It looks bad for us and worse for Zoom.

Thanks,

Katy

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 9, 2020, 6:38am UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/4 "2020-04-09T06:38:35Z")

</div>

Hey @katyle,

We are reviewing your request! (ZOOM-149706)

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![hedaoo.abhishek1993](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/hedaoo.abhishek1993/32/5296_2.png) [@hedaoo.abhishek1993](https://devforum.zoom.us/u/hedaoo.abhishek1993)\
**Post date:** [April 9, 2020, 6:57am UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/5 "2020-04-09T06:57:45Z")

</div>

Hi Tommy,

I am not sure what “token expiry tolerance” is?  
If increased while the old refresh token be still valid after I use it to generate access token?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 10, 2020, 12:02am UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/6 "2020-04-10T00:02:33Z")

</div>

Hey @hedaoo.abhishek1993,

It would be valid for one missed refresh each time the tokens are regenerated.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![hedaoo.abhishek1993](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/hedaoo.abhishek1993/32/5296_2.png) [@hedaoo.abhishek1993](https://devforum.zoom.us/u/hedaoo.abhishek1993)\
**Post date:** [April 10, 2020, 5:55am UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/7 "2020-04-10T05:55:44Z")

</div>

Hi Tommy,  
I am new on the ZOOM and still understanding how the authorization works.

Please confirm below use case if I have understood it correctly.

(Assuming that we have increased refresh token tolerance)  
R - Refresh Token, A- Access Token

1. R1A1 - I have this on two threads, T1 and T2.
2. A1 expires
3. T1 requests for new token using R1. It gets R2A2.
4. Similarly as A1 has expired,T2 also requests for new token using R1.
5. Now that tolerance is increased, will T2 get R2A2 or R3A3? Or request will fails for T2?

---

<div class="post-metadata">

**Author:** ![tommy](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/tommy/32/72769_2.png) [@tommy](https://devforum.zoom.us/u/tommy)\
**Post date:** [April 10, 2020, 6:03am UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/8 "2020-04-10T06:03:02Z")

</div>

Hey @hedaoo.abhishek1993, happy to help!

T2 will get R2A2.

Thanks,  
Tommy

---

<div class="post-metadata">

**Author:** ![DeveloperBot](https://sea2.discourse-cdn.com/flex016/user_avatar/devforum.zoom.us/developerbot/32/12632_2.png) [@DeveloperBot](https://devforum.zoom.us/u/DeveloperBot)\
**Post date:** [August 21, 2020, 8:24pm UTC](https://devforum.zoom.us/t/refresh-token-validity/12093/9 "2020-08-21T20:24:03Z")

</div>


