...
- RefreshTokenValidityPeriod is mentioned in seconds. By default it is valid for one day.
- By default "RenewRefreshTokenForRefreshGrant" set to true,
- we renew the refresh token when refresh grant is used to get an access token --> a new refresh token is issued with a new expiry time
- previous refresh token is then inactive and can no longer be used
- If set false,
- unless refresh token is expired, the same refresh token is returned. (Please refer https://wso2.org/jira/browse/IDENTITY-4298 for a known issue in this flow, for the fix.)
Try Out Scenario with cURL:
...