OAuth - Access Token expiration period?
Does anyone know what the expiration peri开发者_如何学Pythonod of an OAuth Access Token is?
This depends on the organization policy for the Oauth implementation. Typically the lifetime of the token last from several hours to couples of weeks oauth2 Documentation. What can be derived from the Amazon Amazon: Access Tokens, Facebook Facebook:Expiration and Extension of Access Tokens, Salesforce salforce forum, and google documentation is the lifetime of access is usually within 24 hours, typically, 1 hour to 2 hours. The refresh token stay alive for longer period which is used to invalidate the access token. furthermore, A short survey of the desired category application would be helpful. For example, I am currently working on eCommerce app, so, I am going to find out how long is the lifetime of the access token in the other application of the same category like Amazon and wallmart.
Update:
eCommerce applications and payment gateways has the access token lifetime within 10 hours. while, Social media applications has access token lifetime up to six months.
That depends on the provider, but in most cases it's valid until the account holder revokes your access.
Twitter for example - it doesn't expire, but the user can revoke your access.
精彩评论