Hello LIL Tinder,
Thank you for posting question on Microsoft Windows Forum!
Based on the issue description. Well! The plausible explanation to this behavior is that the intermittent invalid_grant error on a mobile client after extended runtimes or multi-device sign-ins typically stems from Refresh Token Rotation race conditions (concurrency) or Authorization Server session/rotation policies (such as token family invalidation via reuse detection). When a refresh token is rotated, any re-use of the previous token or concurrent requests using stale tokens causes the server to reject the grant and potentially revoke the active session.
The suggestion here is to audit client-side refresh concurrency. If the mobile app has multiple background threads or concurrent network calls attempting to refresh an expired access token simultaneously, they will submit the same refresh token. Under Refresh Token Rotation, the authorization server invalidates the old token and issues a new one on the first request. Subsequent concurrent requests then submit the old token, triggering invalid_grant and potentially revoking the entire token family. Implement a "single-flight" mutex or token queue so only one refresh request executes at a time, while concurrent callers await the resulting token. You can verify success by inspecting client network logs during high-concurrency background syncs to ensure only one token endpoint request is dispatched per refresh cycle.
Another suggestion is to check multi-device session and token family policies. When users sign in on multiple devices, identity providers often enforce policies like maximum concurrent sessions, single-session limits, or strict token family revocation where reusing an older token invalidates sibling tokens across all clients. Review your IdP's session management configuration to see if a login on a secondary device explicitly revokes or displaces the refresh token family issued to the primary device. Try to verify this by checking identity provider audit logs to see if an invalid_grant corresponds directly to a subsequent sign-in event from another device.
It is also worth examining whether the error occurs strictly after a fixed time window (absolute lifetime) or period of app inactivity (idle timeout). The fact is that many authorization servers enforce maximum refresh token lifetimes or sliding windows regardless of usage. Try to compare the timestamp when the initial token was issued against the exact moment the invalid_grant occurs to see if it matches the IdP's configured max-age or idle limit.
For further reference.
Hope the above information is helpful!