Prompt
Why is my refresh token not working anymore?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
There are a few common reasons a refresh token suddenly “stops working,” and the exact cause depends on the auth provider and your implementation.
Most common causes
-
Refresh token expired
- Some providers issue refresh tokens that expire after a set time.
- Others use rotation, where each refresh returns a new refresh token and the old one becomes invalid.
-
Refresh token was revoked
- User changed password, signed out, or disconnected the app.
- Admin/security policies revoked it.
- The auth server detected suspicious reuse.
-
You’re reusing an old rotated token
- If your provider uses refresh token rotation, you must store and use the latest refresh token each time.
- If two requests use the same refresh token, one may succeed and the other may fail.
-
Incorrect client configuration
- Wrong client ID/secret.
- Missing
offline_accessscope or equivalent. - Redirect URI mismatch.
- Using the wrong auth grant type or token endpoint.
-
Server-side session expired
- The refresh token may still exist, but the underlying session is gone.
- Some providers invalidate refresh tokens when the session ends.
-
Clock or time skew
- Less common for refresh tokens than access tokens, but if your system time is off, you may think the token is expired or the server may reject related assertions.
-
Token storage bug
- New refresh token is returned, but your app doesn’t save it.
- App caches an old token.
- Multiple devices/instances overwrite each other’s stored token.
What to check
- Look at the exact error response from the token endpoint.
invalid_grantis very common for expired/revoked/rotated tokens.
- Confirm whether your provider uses refresh token rotation.
- Verify your app is persisting the latest refresh token after every refresh.
- Check whether the user/account was recently:
- logged out
- password reset
- consent revoked
- affected by a security policy
- Review token endpoint logs if available.
If you want, paste:
- the error message / response body
- the auth provider (Auth0, Google, Microsoft, Cognito, etc.)
- a redacted version of your refresh flow
…and I can help pinpoint the likely issue.