How do refresh tokens work in Salesforce, and how would you set the policy for a field mobile app?
Suggested answer
When a client completes an interactive flow with the refresh token scope, it receives a refresh token alongside the access token. Access tokens are short-lived; the refresh token is exchanged for new ones without prompting the user again. That is what keeps a mobile app signed in for weeks.
The connected app's refresh token policy is where the lifetime is governed: valid until revoked, immediately expired, expires after a fixed period, or expires if it has not been used for a set period. For a field mobile app I choose the inactivity-based policy. Active engineers are never interrupted, but a device that goes quiet for the threshold period loses its access automatically — which is the practical control for handsets that are lost, resold, or left in a drawer after someone leaves.
The point I make sure lands is that a refresh token is a live credential that survives the identity provider. Disabling someone in Active Directory does not touch it. Offboarding has to deactivate or freeze the Salesforce user and revoke the tokens, or that mobile app keeps working.
Practice content for interview preparation; not an official vendor answer. Verify details against current product documentation.
Community comments (0)
No comments yet.
Sign in or create a free account to add a comment. Comments are moderated before they appear.