CIBA treatment of refresh tokens is somewhat inconsistent or unclear

Issue #76 resolved
Brian Campbell created an issue

The treatment of refresh tokens seems a bit inconsistent with some text sounding like it might imply that RT will/must always be returned. Other text is more clear that it's optional, which is is the case with other OAuth flows/grants, and how it should probably also be throughout CIBA.

Comments (2)

  1. Log in to comment