IAMDevBox
  • Guides
  • Tools
  • Trending
  • Contact
  • Search
Home » Tags

Tag · 2 articles

Refresh Tokens

Jun 4, 2025 · 4 min read

Understanding Token Revocation and When to Use It

Learn how to implement OAuth 2.0 token revocation (RFC 7009) to immediately invalidate access and refresh tokens on logout, security breaches, or permission changes. Includes curl examples for Keycloak, Auth0, and Okta.
Jun 4, 2025 · 3 min read

How OAuth 2.1 Refresh Tokens Work: Best Practices and Expiry

OAuth 2.1 refresh tokens: rotation on every use, reuse detection to catch stolen tokens, expiry lifetime config, and sender-constrained tokens for API security.
IAMDevBox

Identity and access management guides and browser tools for engineers who run Keycloak, ForgeRock, Ping Identity, SailPoint, OAuth 2.0 and SAML in production.

Guides

  • Keycloak
  • OAuth 2.0 & OIDC
  • SAML & SSO
  • ForgeRock & Ping Identity
  • SailPoint IdentityIQ
  • All guides

Tools

  • JWT Decoder
  • PKCE Generator
  • SAML Decoder
  • OAuth 2.0 Playground
  • OIDC Discovery Checker
  • All tools

Resources

  • ForgeRock deployment checklist
  • Trending
  • Search
  • About
  • RSS feed

Connect

  • GitHub
  • YouTube
  • Dev.to
  • Mastodon
  • Contact
© 2026 IAMDevBox. Independent and vendor-neutral. Tools run locally in your browser. Built with Hugo