Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Refresh-token rotation helps OAuth public clients detect replay of a stolen token: after a successful refresh, the authorization server replaces the old refresh token, and later use of that old token can trigger a response. But rotation cannot identify whether the attacker or the legitimate client made the replay request, and it does not make theft harmless. Under current OAuth security guidance, public clients must use rotation or sender-constrained refresh tokens.

What refresh-token rotation does

An access token is presented to a resource server to access protected data or services. A refresh token is sent to the authorization server to obtain new access tokens, so it can be valuable to an attacker who steals it.

With rotation, a successful refresh exchanges the current refresh token for a replacement. The server invalidates the prior token and retains the relationship between the old and new tokens. If the old token is presented again, the server can recognize that it has already been used. This is replay detection: the reuse is evidence that the credential may have been copied.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Rotation does not stop the first unauthorized use of a stolen, still-valid token. Its security value is that subsequent reuse can expose the replay and let the server contain it.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

What current OAuth guidance requires

RFC 9700, the OAuth 2.0 Security Best Current Practice published in January 2025, says refresh tokens issued to public clients must be sender-constrained or use rotation. A public client—such as a browser-based or native app—cannot reliably keep a shared secret confidential. The requirement is therefore to use one of these replay defenses, not necessarily rotation in every deployment. RFC 9700, §§2.2.2 and 4.14.

Sender constraint binds a token to a particular client instance. RFC 9700 gives mutual TLS (mTLS) and Demonstrating Proof of Possession (DPoP) as examples. The appropriate choice depends on what the authorization server and client platform support.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

RFC 6749, the OAuth 2.0 Authorization Framework published in October 2012, establishes the baseline handling rules: refresh tokens are optional, must be kept confidential in storage and transit, and must be transmitted over TLS. When a client can be authenticated, the refresh token must be bound to that client. If the server issues a replacement refresh token, the client must discard the old one and use the new one. RFC 6749, §§1.5 and 6.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

RFC 9700 also says refresh tokens should be limited to the scopes and resource servers the user consented to. It recommends expiration after a period of inactivity, with the interval left to the authorization server, and allows revocation after events such as a password change or authorization-server logout. RFC 9700, §4.14.

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

What reuse detection can—and cannot—tell you

If a server sees an invalidated refresh token again, it can infer that the token was reused. It cannot determine from that request alone whether the attacker or the legitimate client sent it. RFC 9700 describes revoking the active refresh token to stop a possible attack. That containment can also interrupt the legitimate session and require the user to complete authorization again. RFC 9700, §4.14.2.

This is the central trade-off: revoking the active token limits an attacker’s ability to keep minting access tokens, but a false alarm or race can impose a reauthentication cost on the user. Rotation is replay detection and containment, not a way to identify the thief or recover a stolen credential silently.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Rotation and sender constraint compared

Consideration Refresh-token rotation Sender-constrained refresh tokens
Security mechanism Replaces each used token; reuse of an invalidated token can reveal replay. Binds token use to a client instance, for example with mTLS or DPoP.
Deployment fit Useful where the authorization server and client support replacement and reuse detection. Useful where the authorization server and client can establish and maintain the binding.
Replay response Reuse can cause the server to revoke the active token; it cannot identify which party made the replay request. The binding is intended to prevent a copied token from being usable by a party lacking the corresponding proof.
Client implementation Must reliably persist the replacement token and coordinate refresh operations. Must create and provide the required proof of possession; the details depend on the chosen mechanism.
User impact after suspected replay Revocation may require the legitimate user to authorize again. The cited RFC guidance does not prescribe a universal recovery experience.

RFC 9700 recognizes both defenses but does not prescribe one for every system. Choose based on whether client-instance binding is feasible, whether mTLS or DPoP is supported across the deployment, and how the application will handle recovery when a token is rejected.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Implement rotation without losing the active credential

  1. Replace atomically. After a successful refresh, persist the returned refresh token reliably and treat it as the current credential. Discard the old token as required by RFC 6749. A crash or failed write between receiving and storing the replacement can leave the client with an invalid token.
  2. Serialize refresh operations. Coordinate requests so two simultaneous renewals do not both try to use the same one-time refresh token. Auth0’s Swift SDK documentation notes that concurrent renewals can produce a reused-token error and recommends its thread-safe credentials manager or otherwise synchronizing renewals. This is an Auth0 SDK implementation example, not a rule for every provider. Auth0 Swift documentation.
  3. Handle rejection as a session-recovery event. If the provider reports token reuse or invalidation, do not keep retrying the old token. Follow the provider’s recovery path; the user may need to authorize again.
  4. Retain baseline protections. Store refresh tokens securely, transmit them only over TLS, and keep their scope and resource-server access narrow. These controls reduce exposure but do not replace replay defense.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Provider behavior is product-specific

Auth0 documents rotation as enabled by default for public third-party single-page and native applications, with settings for rotation, leeway, and token lifetime. Those details apply to the documented Auth0 application types; they are not OAuth-wide defaults. Check the current documentation and configuration for the authorization server and client type you actually deploy. Auth0 refresh-token rotation documentation.

Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Browser-based applications also have dedicated guidance in RFC 10017, OAuth 2.0 for Browser-Based Applications: it says browser apps must either rotate refresh tokens on each use or use sender-constrained refresh tokens. Verify the applicable standards version and provider behavior when implementing a browser app. RFC 10017.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.