Keep an AI agent’s OAuth tokens secure by limiting what they authorize, storing them as credentials, constraining replay where the provider supports it, and handling refresh, expiry, and revocation as routine lifecycle events. A refresh token is especially sensitive: anyone who can use it may be able to obtain new access tokens within the user’s granted authority.
Start with a secure OAuth flow
Token security begins before an agent stores its first credential. Use the authorization code flow with Proof Key for Code Exchange (PKCE) where appropriate. RFC 9700, the IETF’s OAuth 2.0 Security Best Current Practice published in January 2025, requires PKCE for public clients and recommends it for confidential clients. Use the S256 challenge method; the RFC identifies it as the current method that does not expose the verifier in the authorization request.
Make each PKCE challenge specific to its authorization transaction and bind it to the client and user agent. Protect the redirect endpoint against cross-site request forgery (CSRF). If a client interacts with multiple authorization servers, apply a mix-up defense. Do not accept arbitrary redirect destinations from request parameters. Avoid the implicit flow and avoid putting access tokens in authorization-response URLs, where they can be exposed or replayed.
Give the agent only the access it needs
Request only the scopes required for the workflow. Restrict an access token’s audience to one resource server where possible, or to a small set when necessary, and have each resource server check that the audience is intended for it. Bind refresh tokens to the scopes and resources the user approved. These controls limit the impact of a leaked token and prevent a refresh token from being used to expand the original authorization. RFC 9700 describes these protections.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
For an AI agent, least privilege should also shape the tool boundary: the model should receive only the data and actions needed for a task, not raw credentials. Keep OAuth operations in the application’s trusted runtime and expose narrowly defined API actions to the agent. This reduces unnecessary credential exposure; it cannot protect tokens if the runtime or its secrets are compromised.
Store tokens and keep them out of telemetry
Treat both access tokens and refresh tokens as credentials. Google for Developers’ Best Practices | Authorization Resources advises storing tokens securely at rest, never transmitting them in plain text, and revoking and deleting them when they are no longer needed. For applications holding tokens for multiple users, Google recommends encrypting server-side tokens.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
For a server-side agent
- Keep tokens in a private datastore with encryption at rest and strict access controls; do not expose the token store to the public internet.
- Limit which services and operators can read or modify stored credentials. Protect backups and administrative access as well as the primary datastore.
- Keep raw token values out of logs, traces, prompts, crash reports, and analytics. Redact authorization headers and token-bearing fields before data reaches observability systems.
RFC 9700 explicitly says resource servers must not store or transfer access tokens in plaintext. The logging and access-control steps above apply the same credential-protection principle to an agent’s surrounding infrastructure.
For a device-resident agent
Use the operating system’s secure credential storage where available. Google lists Android Keystore, Apple Keychain Services, and Windows Credential Locker as examples. The appropriate choice depends on the deployment; a file readable by the application is not equivalent to protected platform storage.
Do these 3 things before closing this tab:
1Scan for outdated or missing drivers - takes under a minute2Clear out junk files and repair common Windows errors3Fix the driver behind crashes, sound loss and screen glitchesRank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Reduce the risk of token replay
A bearer token can be used by whoever possesses it. Where the authorization server and resource server support it, consider sender-constrained tokens, which require proof that the caller controls associated key material. RFC 9700 recommends this approach, including mutual TLS (mTLS) or Demonstrating Proof of Possession (DPoP).
| Option | How it constrains use | Operational fit and trade-off |
|---|---|---|
| DPoP | The client signs application-level proofs with a public/private key pair. DPoP is specified in RFC 9449, published in September 2023. | Can be used with public clients and combined with confidential-client authentication. Verify provider support and protect the private key. |
| Mutual TLS | Token use is bound to client certificate key material and the TLS connection. The approach is specified in RFC 8705, published in February 2020. | Fits deployments able to provision and maintain client certificates across the client and resource server. Verify support and plan certificate lifecycle operations. |
These controls reduce the value of a stolen token when the attacker does not also possess the associated key. They do not make a compromised agent host safe: protection is undermined if an attacker obtains both the token and its key material. Protect keys with platform security or a hardware or software security module where the architecture supports it.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Choose refresh-token replay protection deliberately
For public clients, RFC 9700 requires refresh tokens to be sender-constrained or rotated. These are different controls, and the authorization server must support the chosen option.
Rotation
With refresh-token rotation, a successful refresh returns a replacement token and invalidates the previous one. If the old token is used again, the server can detect reuse. Because it cannot know whether the legitimate client or an attacker made that request, it may revoke the active token; the legitimate user may then need to authorize the client again.
Best Value
- POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Account for this behavior in the agent’s refresh implementation. Serialize refreshes for a given grant so concurrent tasks do not race to use the same token. Persist the replacement before allowing another refresh attempt. These are application-level safeguards for working with rotation, not additional requirements stated by RFC 9700.
Sender constraint
DPoP or mTLS ties use of a token to proof of possession of key material rather than relying only on possession of the token. Select an option based on client architecture, provider and resource-server support, and the ability to safeguard keys or operate certificates. Do not assume either option is available for every API.
Make expiry, revocation, and refresh failure normal cases
Do not assume a refresh token remains valid indefinitely. RFC 9700 recommends that authorization servers expire refresh tokens after inactivity; the timing is determined by server policy and may depend on the client or grant’s sensitivity. Servers may also revoke tokens after events such as a password change or logout. Google’s guidance likewise tells applications to account for invalidation or expiration and decide whether to prompt at the next sign-in or clean up associated data.
- On a refresh failure, stop using the rejected credential. Do not keep retrying in a loop; repeated attempts can worsen rate limits or a token-reuse incident.
- Update local credential state. Clear or quarantine the stored token according to the application’s policy, and prevent queued agent work from continuing to use it.
- Recover through authorization when required. Ask the user to authorize again if the provider requires a new grant. If the connection is no longer needed, revoke and delete its credentials and clean up associated data as appropriate.
Exact expiry periods, revocation behavior, and recovery screens vary by provider and deployment. Follow the authorization server’s documented policy rather than hard-coding a universal token lifetime.
Use a layered design, not a single safeguard
OAuth token protection depends on controls working together: a secure flow, narrow authorization, private credential storage, minimal telemetry exposure, replay resistance where supported, and a deliberate recovery path. None prevents misuse after an attacker compromises the agent host and obtains the credentials or key material it needs.

