Azure OAuth2.0颁发的refresh_token及指定接口返回的过期时间咨询
Azure AD OAuth2.0 Refresh Token Expiry Details
Great question—let's break this down clearly, since refresh token behavior in Azure AD has a few important nuances to keep in mind.
1. General Expiry for Azure AD OAuth2.0 Refresh Tokens
By default, Azure AD issues refresh tokens with a 90-day validity period. But there are a few caveats to this:
- If you regularly use the refresh token to request new access tokens (before it expires), Azure AD will often return a new refresh token (a "rolling refresh") with a fresh 90-day expiry window. This lets you maintain valid credentials as long as the token is used periodically.
- If a refresh token goes unused for 90 days straight, it will expire permanently—you’ll have to prompt the user to re-authenticate to get a new set of tokens.
- Some organizational policies (like conditional access rules or strict security settings) can shorten this expiry period for specific apps or user groups.
2. Refresh Token Expiry from the /oauth2/v2.0/token Endpoint
When you call the POST https://login.microsoftonline.com/{tenant}/oauth2/v2.0/token endpoint, you’ll notice the response (like the example you shared) doesn’t include a direct refresh_token_expires_in field (unlike the expires_in value for access tokens).
Here’s what you need to know about this specific scenario:
- The refresh token returned here still follows the default 90-day expiry rule mentioned above, unless modified by organizational policies.
- There’s no way to get the exact expiry timestamp directly from this token response. If you need to track it, you have two practical options:
- Track the timestamp when you receive the refresh token, and assume a 90-day window (adjusting for any known organizational policies your tenant enforces).
- Use the Microsoft Graph API to check the token’s validity or get more lifecycle details (though this requires additional permissions for your app).
Example response from the endpoint:
{ "access_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJSUzI1NiIsIng1dCI6Ik5HVEZ2ZEstZnl0aEV1Q...", "token_type": "Bearer", "expires_in": 3599, "scope": "https%3A%2F%2Fgraph.microsoft.com%2Fmail.read", "refresh_token": "AwABAAAAvPM1KaPlrEqdFSBzjqfTGAMxZGUTdM0t4B4...", "id_token": "eyJ0eXAiOiJKV1QiLCJhbGciOiJub25lIn0.eyJhdWQiOiIyZDRkMTFhMi1mODE0LTQ2YTctOD..." }
内容的提问来源于stack exchange,提问作者Paras
相关产品推荐
相关产品推荐

