just a minor issue "In addition, this specification does not provide a mechanism for refresh token rotation."
The spec provides a mechanisms. It allows for the issuance of a new refresh token with every request to referesh an access token.
regards, Torsten. _______________________________________________ OAuth mailing list OAuth@ietf.org https://www.ietf.org/mailman/listinfo/oauth