Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Protecting OAuth credentials takes more than encrypting a database. Keep refresh tokens confidential in transit and storage, choose storage and key controls for your deployment’s threat model, implement replay defenses at the authorization server, and prevent tokens and session identifiers from entering logs.

Why refresh tokens need special protection

A refresh token can let whoever possesses it obtain new access tokens and act with the authority granted to the client. Treat it as a high-value secret, not as ordinary application data. RFC 6749 requires refresh tokens to remain confidential in transit and storage, be shared only between the authorization server and the client to which they were issued, and travel over TLS. RFC 6749

Access tokens are sensitive too: RFC 9700 says resource servers must treat them like other sensitive secrets and must not store or transfer them in plaintext. RFC 9700

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Who is responsible for rotation and replay defense?

The authorization server implements refresh-token rotation or sender constraint. The client is responsible for securely handling the credentials it receives, storing them appropriately, and avoiding their exposure. These are complementary controls, not interchangeable jobs.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Rotation: replace the token on every refresh

RFC 9700, the IETF’s OAuth 2.0 Security Best Current Practice published in January 2025, requires public clients’ refresh tokens to be sender-constrained or use refresh-token rotation. With rotation, the authorization server issues a replacement refresh token and invalidates the one just used. It also retains the relationship between tokens in the lineage so reuse of an invalidated token can signal replay.

If a stolen token and the legitimate client both get used, the server may detect reuse and revoke the active refresh token. That limits continued use of the compromised lineage, but it does not make replay impossible; the legitimate user may have to authorize again. RFC 9700

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Sender constraint: bind use to client proof

Sender-constrained tokens require proof tied to a particular client or key. RFC 9700 recognizes mutual TLS and DPoP as approaches. This can be an alternative to rotation for a public client when the authorization server supports it and the client can protect and present the associated key material. If an attacker obtains both the token and its associated key, the binding’s protection is weakened. RFC 9700

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where should token state be stored?

There is no single storage layer that fits every deployment. Start with the threat model and retain as little sensitive state as the application needs. Consider what an attacker could reach: a stolen device or disk, a database disclosure, host compromise, or a compromised running application. OWASP’s Cryptographic Storage Cheat Sheet discusses encryption at application, database, filesystem, and hardware layers.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Layer or control Useful protection to consider Important limit
Application-level encryption Can separate stored ciphertext from the application’s ordinary data path, depending on key access and design. A compromised running application may still access tokens or request decryption.
Database encryption Can help address database or storage disclosure, depending on where keys are held. Does not by itself prevent a live application or database process with authorized access from reading data.
Filesystem or hardware encryption Can help protect data on storage media, including against some physical-theft scenarios. Hardware encryption does not protect against remote server compromise.
Minimize retained state Reduces the amount of sensitive material available to expose or misuse. Does not replace confidentiality controls for tokens that must be retained.

Encryption at rest is not a shield against every compromise. In particular, encryption that a live application can transparently use will not necessarily protect token values if that application is taken over. Select a layer based on the threat it is meant to address rather than treating the presence of encryption as proof that the vault is safe.

How should encryption keys be managed?

Protect key material separately from the encrypted token state. OWASP identifies HSMs, virtual HSMs, cloud key vaults, and external secrets-management systems as possible options. Centralized key management and rotation can help, but dedicated systems add administrative and integration complexity; use one when its controls and operating costs match the deployment’s requirements, not as a universal prerequisite.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Do not hard-code encryption keys or check them into version control.
  • Avoid storing keys beside the secrets they protect unless the keys themselves are protected, for example through envelope encryption.
  • For symmetric encryption, OWASP recommends AES with a key of at least 128 bits and ideally 256 bits, using a secure mode.
  • Use maintained cryptographic libraries rather than designing a custom storage scheme.

When evaluating a key-custody design, compare the threat it covers, separation of keys and ciphertext, access policy, rotation and revocation support, audit and recovery capabilities, and operational overhead. OWASP Cryptographic Storage Cheat Sheet

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How can logs stay useful without exposing credentials?

Do not log raw access tokens, refresh tokens, or session IDs in plaintext. Also exclude authorization headers, cookies, and sensitive request or response bodies before logs reach collection and indexing systems. OWASP recommends avoiding sensitive data in logs; when session correlation is needed, it suggests replacing session identifiers with hashed values. OWASP Secrets Management Cheat Sheet OWASP Session Management Cheat Sheet

Best Value
Yubico - YubiKey 5C - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB, FIDO Certified - Protect Your Online Accounts (5C)
  • POWERFUL SECURITY KEY: The YubiKey 5 is a versatile physical passkey that protects your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 secures 100+ of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 via USB and tap it to authenticate. No batteries, no internet connection, and no extra fees required.
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

A practical pattern is an allow-listed event schema. Record operational facts such as event type, time, outcome, route or operation, and a non-secret actor or correlation identifier. If correlation requires linking events to a session, use a suitable hash rather than the session ID itself. Validate the schema at the logging boundary so new fields do not silently capture credentials.

Putting the controls together

  1. Define the threat model. Identify whether the key concern is physical theft, database disclosure, host compromise, or compromise of the running application, and minimize the sensitive state retained.
  2. Choose storage and key custody together. Select an encryption layer and a separate key-management approach that address those threats; avoid hard-coded keys and protect any co-located key material.
  3. Set the public-client replay defense. Ensure the authorization server supports sender constraint or refresh-token rotation. Account for the possibility that detected reuse revokes the active lineage and requires the user to authorize again.
  4. Constrain log fields. Allow-list operational fields, exclude credentials and session identifiers, and use a hashed or otherwise non-secret identifier only when correlation is necessary.
  5. Review the live access path. Check which application components can read tokens or use decryption keys, because at-rest encryption alone cannot prevent access by a compromised running service.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.