Use the token endpoint response and sign-in conditions to separate five common causes of invalid_grant during refresh:
- Expired or invalid refresh token
- A refresh token can expire, be revoked, or no longer have sufficient privileges.
- When that happens, the app must handle the token endpoint error and start a new interactive sign-in flow.
- For Microsoft identity platform,
invalid_grantmeans the grant is invalid or expired and a new authorization request is required.
- Refresh token rotation
- When a new refresh token is returned, replace the old one immediately.
- Old refresh tokens are expected to be discarded after a successful refresh.
- If the app keeps using an older stored token after a newer one was issued, intermittent refresh failures can occur.
- Multi-device and public client behavior
- For public clients, refresh tokens can be device-bound in some scenarios.
- If users sign in on multiple devices, verify that each device stores and uses its own latest refresh token and does not overwrite another device’s token state.
- Do not assume a refresh token will remain valid for any fixed period; the app should always be prepared for reauthentication.
- Session and platform lifetime limits
- Single-page apps using a redirect URI registered as
spahave refresh tokens that expire after 24 hours and must rerun the authorization code flow interactively every 24 hours. - For mobile and desktop public client scenarios in the provided guidance, there is no supported way to extend a 24-hour inactivity window when that behavior applies.
- Conditional Access persistent session settings affect browser sessions, not mobile or desktop app token lifetimes.
- Single-page apps using a redirect URI registered as
- Revocation and policy-driven invalidation
- Refresh tokens can become invalid after events such as password changes, admin revocation, session reset, or renewed consent requirements.
- In those cases, the correct recovery path is reauthentication.
A practical troubleshooting flow:
- Capture the full token error payload
- Log
error,error_description,error_codes,timestamp,trace_id, andcorrelation_idfrom the/tokenresponse. - These fields are the primary diagnostics for token endpoint failures.
- Log
- Verify the refresh request itself
- Confirm the request includes the required refresh token grant parameters.
- Missing required parameters cause
invalid_request, while an expired or invalid grant causesinvalid_grant.
- Audit refresh token storage and replacement logic
- After every successful refresh, check whether a new
refresh_tokenwas returned. - If returned, persist it atomically and stop using the previous token.
- This is the most important check for long-running apps and intermittent failures.
- After every successful refresh, check whether a new
- Correlate failures with user events
- Check whether failures started after password changes, sign-ins on another device, consent changes, or admin/session revocation.
- If yes, treat the token as no longer recoverable and force sign-in.
- Check client type assumptions
- If the app is a mobile or desktop public client, do not design around a guaranteed long refresh token lifetime.
- If the app spans devices or regions, verify the registration model matches the app architecture, because some public-client refresh tokens are only guaranteed to refresh on the same device.
- Handle failure correctly in code
- On
invalid_grant, stop retrying the same refresh token in a loop. - Clear the cached invalid token set and trigger a fresh authorization flow.
- On
- Do not inspect token contents for APIs not owned by the app
- Use the token endpoint response and server-side error metadata for diagnostics instead of relying on token parsing assumptions.
If the app uses Azure App Service authentication, also distinguish between the App Service session and the identity provider token:
- App Service authenticated session: 8-hour session with a default 72-hour grace period, refreshable through
/.auth/refresh. - Identity provider access tokens: no grace period after expiry.
- Microsoft identity platform and OAuth 2.0 authorization code flow
- Manage OAuth tokens in Azure App Service
- Get access and refresh tokens
- MSAL refresh token expires after 24 hours for mobile and desktop app when using OTP - Microsoft Q&A
- How do I fix an Underlying error messageAADSTS50173: The provided grant has expired due to it being revoked, a fresh auth token is needed. - Microsoft Q&A