Announcements

Help Wizard

Step 1

NEXT STEP

PKCE refresh token storage

PKCE refresh token storage

I'm currently building a SPA that communicates with the Spofity API using the Authorization Code with PKCE Flow.

How do I safely store the refresh token so the user won't need to grant authorization everytime it uses the application? My worriy is that if I use the browser's local storage, a malicious third party might manage to get access to the refresh token, and be able to generate an access token form it.

Reply
0 Replies

Suggested posts

Let's introduce ourselves!

Hey there you, ย  Yeah, you!ย 😁 ย  Welcome - we're glad you joined the Spotify Community! ย  While you here, let's have a fun game and getโ€ฆ

ModeratorStaff / Moderator/ 4 years ago  in Social & Random