Beta

Create a tenant

A new tenant starts with its own users, OAuth settings, audit history and logs. You are its first Tenant Admin.

BTL Admin

L30 · OAUTH 2.0

Refresh, then replay

Refresh an access token, then present the replaced refresh token again and watch the whole chain stop working.

Planned

Steps

  1. Run the code flow for a client allowed to use refresh tokens, requesting offline access.

    What the server will check: A token exchange that issued a refresh token.

  2. Exchange the refresh token for a new access token with curl.

    What the server will check: A successful refresh that returned a replacement refresh token.

  3. Present the original refresh token again.

    What the server will check: The reused refresh token was rejected.

    Only one party should hold the newest refresh token. Seeing an old one again suggests a copy exists.

  4. Try the replacement refresh token.

    What the server will check: The replacement was also rejected.

    Your tenant revokes the whole chain when it detects reuse, so the thief and the legitimate client both have to start again.

When it opens

This lab is planned. It opens when these are in place:

  • Lab setup and cleanup in your test tenant
  • The lab callback page

The server checks your test tenant's history for this attempt. You can review the events yourself in your tenant's Audit and Logs.

Learn the theory

Back to all labs

We value your privacy

We use cookies and similar technologies to enhance your browsing experience, and analytics to understand our traffic. By clicking "Allow All", you consent to optional analytics. Cookie Policy

The Lab