Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Refresh-token rotation helps OAuth public clients detect replay of a stolen token: after a successful refresh, the authorization server replaces the old refresh token, and later use of that old token can trigger a response. But rotation cannot identify whether the attacker or the legitimate client made the replay request, and it does not make theft harmless. Under current OAuth security guidance, public clients must use rotation or sender-constrained refresh tokens.
What refresh-token rotation does
An access token is presented to a resource server to access protected data or services. A refresh token is sent to the authorization server to obtain new access tokens, so it can be valuable to an attacker who steals it.
With rotation, a successful refresh exchanges the current refresh token for a replacement. The server invalidates the prior token and retains the relationship between the old and new tokens. If the old token is presented again, the server can recognize that it has already been used. This is replay detection: the reuse is evidence that the credential may have been copied.
Rotation does not stop the first unauthorized use of a stolen, still-valid token. Its security value is that subsequent reuse can expose the replay and let the server contain it.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
What current OAuth guidance requires
RFC 9700, the OAuth 2.0 Security Best Current Practice published in January 2025, says refresh tokens issued to public clients must be sender-constrained or use rotation. A public client—such as a browser-based or native app—cannot reliably keep a shared secret confidential. The requirement is therefore to use one of these replay defenses, not necessarily rotation in every deployment. RFC 9700, §§2.2.2 and 4.14.
Sender constraint binds a token to a particular client instance. RFC 9700 gives mutual TLS (mTLS) and Demonstrating Proof of Possession (DPoP) as examples. The appropriate choice depends on what the authorization server and client platform support.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
RFC 6749, the OAuth 2.0 Authorization Framework published in October 2012, establishes the baseline handling rules: refresh tokens are optional, must be kept confidential in storage and transit, and must be transmitted over TLS. When a client can be authenticated, the refresh token must be bound to that client. If the server issues a replacement refresh token, the client must discard the old one and use the new one. RFC 6749, §§1.5 and 6.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11RFC 9700 also says refresh tokens should be limited to the scopes and resource servers the user consented to. It recommends expiration after a period of inactivity, with the interval left to the authorization server, and allows revocation after events such as a password change or authorization-server logout. RFC 9700, §4.14.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
What reuse detection can—and cannot—tell you
If a server sees an invalidated refresh token again, it can infer that the token was reused. It cannot determine from that request alone whether the attacker or the legitimate client sent it. RFC 9700 describes revoking the active refresh token to stop a possible attack. That containment can also interrupt the legitimate session and require the user to complete authorization again. RFC 9700, §4.14.2.
This is the central trade-off: revoking the active token limits an attacker’s ability to keep minting access tokens, but a false alarm or race can impose a reauthentication cost on the user. Rotation is replay detection and containment, not a way to identify the thief or recover a stolen credential silently.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Rotation and sender constraint compared
| Consideration | Refresh-token rotation | Sender-constrained refresh tokens |
|---|---|---|
| Security mechanism | Replaces each used token; reuse of an invalidated token can reveal replay. | Binds token use to a client instance, for example with mTLS or DPoP. |
| Deployment fit | Useful where the authorization server and client support replacement and reuse detection. | Useful where the authorization server and client can establish and maintain the binding. |
| Replay response | Reuse can cause the server to revoke the active token; it cannot identify which party made the replay request. | The binding is intended to prevent a copied token from being usable by a party lacking the corresponding proof. |
| Client implementation | Must reliably persist the replacement token and coordinate refresh operations. | Must create and provide the required proof of possession; the details depend on the chosen mechanism. |
| User impact after suspected replay | Revocation may require the legitimate user to authorize again. | The cited RFC guidance does not prescribe a universal recovery experience. |
RFC 9700 recognizes both defenses but does not prescribe one for every system. Choose based on whether client-instance binding is feasible, whether mTLS or DPoP is supported across the deployment, and how the application will handle recovery when a token is rejected.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Implement rotation without losing the active credential
- Replace atomically. After a successful refresh, persist the returned refresh token reliably and treat it as the current credential. Discard the old token as required by RFC 6749. A crash or failed write between receiving and storing the replacement can leave the client with an invalid token.
- Serialize refresh operations. Coordinate requests so two simultaneous renewals do not both try to use the same one-time refresh token. Auth0’s Swift SDK documentation notes that concurrent renewals can produce a reused-token error and recommends its thread-safe credentials manager or otherwise synchronizing renewals. This is an Auth0 SDK implementation example, not a rule for every provider. Auth0 Swift documentation.
- Handle rejection as a session-recovery event. If the provider reports token reuse or invalidation, do not keep retrying the old token. Follow the provider’s recovery path; the user may need to authorize again.
- Retain baseline protections. Store refresh tokens securely, transmit them only over TLS, and keep their scope and resource-server access narrow. These controls reduce exposure but do not replace replay defense.
Provider behavior is product-specific
Auth0 documents rotation as enabled by default for public third-party single-page and native applications, with settings for rotation, leeway, and token lifetime. Those details apply to the documented Auth0 application types; they are not OAuth-wide defaults. Check the current documentation and configuration for the authorization server and client type you actually deploy. Auth0 refresh-token rotation documentation.
Best Value
- The information below is per-pack only
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
Browser-based applications also have dedicated guidance in RFC 10017, OAuth 2.0 for Browser-Based Applications: it says browser apps must either rotate refresh tokens on each use or use sender-constrained refresh tokens. Verify the applicable standards version and provider behavior when implementing a browser app. RFC 10017.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

