OpenIddict设备码流中/connect/token未返回Refresh Token问题
1. Register the offline_access Scope
Your server configuration is missing the offline_access scope, which is mandatory for issuing refresh tokens. Add it to the list of registered scopes:
options.RegisterScopes( OpenIddictConstants.Scopes.Email, OpenIddictConstants.Scopes.Profile, OpenIddictConstants.Scopes.Roles, OpenIddictConstants.Scopes.OfflineAccess // Add this line );
2. Ensure the Client Requests offline_access
When your client initiates the device code flow (via the /connect/device endpoint), it must include offline_access in the scope parameter. Example request:
POST /connect/device HTTP/1.1 Content-Type: application/x-www-form-urlencoded client_id=your_client_id&scope=openid email profile roles offline_access
3. Confirm Server Configuration
You already have AllowRefreshTokenFlow() enabled in your server setup, which is correct. If you use explicit client registrations, ensure the client is allowed to use refresh tokens (via AllowRefreshTokenFlow() on the client configuration).
Key Note
OpenIddict only issues refresh tokens when the offline_access scope is explicitly requested and granted. Without this scope, even if the server allows refresh token flow, no refresh token will be returned in the /connect/token response.
内容的提问来源于stack exchange,提问作者Haythem Tlili

