- Home
- All questions
- Question 351
CISSP study material · question 351 of 500
Which two statements about OAuth 2.0 refresh tokens match RFC 6749? Choose two.
Show the answer
Answer: C. Whether one is issued at all is at the authorization server's discretion.
B. They obtain new access tokens at the same scope or narrower, never wider.
Refresh tokens obtain new access tokens with identical or narrower scope when the current one expires, and issuing a refresh token is optional at the authorization server's discretion.
Source: RFC 6749 (IETF) — RFC 6749 > 1.5 Refresh Token