You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Azure OAuth2.0颁发的refresh_token及指定接口返回的过期时间咨询

Azure AD OAuth2.0 Refresh Token Expiry Details

Great question—let's break this down clearly, since refresh token behavior in Azure AD has a few important nuances to keep in mind.

1. General Expiry for Azure AD OAuth2.0 Refresh Tokens

By default, Azure AD issues refresh tokens with a 90-day validity period. But there are a few caveats to this:

  • If you regularly use the refresh token to request new access tokens (before it expires), Azure AD will often return a new refresh token (a "rolling refresh") with a fresh 90-day expiry window. This lets you maintain valid credentials as long as the token is used periodically.
  • If a refresh token goes unused for 90 days straight, it will expire permanently—you’ll have to prompt the user to re-authenticate to get a new set of tokens.
  • Some organizational policies (like conditional access rules or strict security settings) can shorten this expiry period for specific apps or user groups.

2. Refresh Token Expiry from the /oauth2/v2.0/token Endpoint

When you call the POST https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token endpoint, you’ll notice the response (like the example you shared) doesn’t include a direct refresh_token_expires_in field (unlike the expires_in value for access tokens).

Here’s what you need to know about this specific scenario:

  • The refresh token returned here still follows the default 90-day expiry rule mentioned above, unless modified by organizational policies.
  • There’s no way to get the exact expiry timestamp directly from this token response. If you need to track it, you have two practical options:
    • Track the timestamp when you receive the refresh token, and assume a 90-day window (adjusting for any known organizational policies your tenant enforces).
    • Use the Microsoft Graph API to check the token’s validity or get more lifecycle details (though this requires additional permissions for your app).

Example response from the endpoint:

{ 
  "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ik5HVEZ2ZEstZnl0aEV1Q...", 
  "token_type": "Bearer", 
  "expires_in": 3599, 
  "scope": "https%3A%2F%2Fgraph.microsoft.com%2Fmail.read", 
  "refresh_token": "AwABAAAAvPM1KaPlrEqdFSBzjqfTGAMxZGUTdM0t4B4...", 
  "id_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJub25lIn0.eyJhdWQiOiIyZDRkMTFhMi1mODE0LTQ2YTctOD..." 
}

内容的提问来源于stack exchange,提问作者Paras

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 08:30:34