<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Authorization Code Flow - misleading documentation in Spotify for Developers</title>
    <link>https://community.spotify.com/t5/Spotify-for-Developers/Authorization-Code-Flow-misleading-documentation/m-p/5518199#M8266</link>
    <description>&lt;P&gt;&lt;A href="https://developer.spotify.com/documentation/general/guides/authorization/code-flow/#request-a-refreshed-access-token" target="_blank" rel="noopener"&gt;https://developer.spotify.com/documentation/general/guides/authorization/code-flow/#request-a-refreshed-access-token&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The documentation doesn't mentioned that a "refresh_token" is returned in the response when you refresh your access token. This is important because you can only use refresh tokens once and are required to use the newly returned one in the next refresh request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I've misunderstood the endpoint, the documentation should at least say that a "refresh_token" &lt;EM&gt;is not&lt;/EM&gt; returned during a token refresh.&lt;/P&gt;</description>
    <pubDate>Thu, 09 Mar 2023 22:41:08 GMT</pubDate>
    <dc:creator>benfernandes</dc:creator>
    <dc:date>2023-03-09T22:41:08Z</dc:date>
    <item>
      <title>Authorization Code Flow - misleading documentation</title>
      <link>https://community.spotify.com/t5/Spotify-for-Developers/Authorization-Code-Flow-misleading-documentation/m-p/5518199#M8266</link>
      <description>&lt;P&gt;&lt;A href="https://developer.spotify.com/documentation/general/guides/authorization/code-flow/#request-a-refreshed-access-token" target="_blank" rel="noopener"&gt;https://developer.spotify.com/documentation/general/guides/authorization/code-flow/#request-a-refreshed-access-token&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The documentation doesn't mentioned that a "refresh_token" is returned in the response when you refresh your access token. This is important because you can only use refresh tokens once and are required to use the newly returned one in the next refresh request.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If I've misunderstood the endpoint, the documentation should at least say that a "refresh_token" &lt;EM&gt;is not&lt;/EM&gt; returned during a token refresh.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Mar 2023 22:41:08 GMT</pubDate>
      <guid>https://community.spotify.com/t5/Spotify-for-Developers/Authorization-Code-Flow-misleading-documentation/m-p/5518199#M8266</guid>
      <dc:creator>benfernandes</dc:creator>
      <dc:date>2023-03-09T22:41:08Z</dc:date>
    </item>
  </channel>
</rss>

