Symptom
- Unexpected behavior regarding refresh token rotation on the OIDC token endpoint.
- The same refresh token can be used successfully twice; the third attempt fails.
- Error: invalid_grant — "The provided authorization code or refresh token is invalid."
Read more...
Environment
- SAP Customer Data Cloud
- REST API
- OpenID Connect (OIDC)
Product
SAP Customer Data Cloud all versions
Keywords
refresh token rotation, grace period, invalid_grant, oidc token endpoint, token reuse, same tokens returned, introspect endpoint, access token, refresh token invalid , KBA , CEC-PRO-API , Core REST API & Server SDKs (JWT / PHP / Java) , Problem
About this page
This is a preview of a SAP Knowledge Base Article. Click more to access the full version on SAP for Me (Login required).Search for additional results
Visit SAP Support Portal's SAP Notes and KBA Search.
SAP Knowledge Base Article - Preview