openid / oid4vc-haip-sd-jwt-vc

High Assurance Profile of OID4VP and OID4VCI using SD-JWT VC and mdocs that is privacy preserving, secure, and meets regulatory requirements
27 stars 7 forks source link

relax refresh tokens requirement? #41

Open Sakurann opened 1 year ago

Sakurann commented 1 year ago

I was surprised to find that FAPI does not mandate refresh tokens. maybe this profile should also relax mandating refresh tokens..

the use of refresh tokens instead of long-lived access tokens for both public and confidential clients is recommended.

tlodderstedt commented 1 year ago

Agree to reconsider. We should be very sure and clear why we think refresh tokens are needed.

In my opinion, refresh tokens can help to achieve a better UX in the following cases:

peppelinux commented 7 months ago

I agree, in the italian impl profile we do not support the refresh token, as mentioned here

https://github.com/italia/eudi-wallet-it-docs/issues/154