Prompt
What should I use for account linking and refresh tokens?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
For account linking and refresh tokens, the best choice is usually:
1) Account linking
Use a stable internal user ID in your app, and store external provider identities separately.
Recommended model
- users
id(your internal user ID)- profile fields
- external_accounts
user_idprovider(Google, GitHub, Apple, etc.)provider_user_id- provider profile info
- tokens if needed
Why this works
- Lets one app user link multiple providers
- Avoids depending on email as the primary identifier
- Makes it easy to merge/link accounts later
Linking flow
- User signs in with a provider
- If provider identity already exists, log them in
- If not, create or prompt to link with an existing account
- If email matches an existing account, only auto-link if you trust email verification from that provider and your security policy allows it
2) Refresh tokens
Use refresh tokens only for long-lived sessions and rotate them.
Best practices
- Store refresh tokens server-side, not in local storage
- Prefer httpOnly secure cookies for browser apps
- Use refresh token rotation
- Revoke old tokens on use or on logout
- Keep access tokens short-lived
Storage
- Web app: httpOnly + Secure + SameSite cookies
- Mobile/desktop: secure OS storage (Keychain, Keystore, Credential Manager)
- Backend-to-backend: encrypted secret storage, not user-facing storage
Token strategy
- Access token: short TTL, e.g. 5–15 minutes
- Refresh token: longer TTL, e.g. days or weeks
- Reissue access token using refresh token
- Rotate refresh token every time it’s used
3) If you’re using OAuth/OIDC
For most apps:
- Use OpenID Connect for login
- Use Authorization Code + PKCE
- Use refresh token rotation
- Store provider access/refresh tokens only if your app needs to call provider APIs on the user’s behalf
4) Practical recommendation
If you want a simple, secure default:
- Use OIDC
- Maintain your own
userstable - Add
linked_accountsfor providers - Use short-lived access tokens
- Use rotating refresh tokens
- Store refresh tokens in httpOnly secure cookies for web
If you tell me your stack (web/mobile/backend, auth provider, and whether you need to call third-party APIs), I can suggest a concrete setup and schema.