# Oauth refresh token, best workflow?

**URL:** https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962
**Category:** General
**Tags:** security
**Created:** [23 May 2022 10:51 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962 "2022-05-23T10:51:48Z")
**Posts on this page:** 11
**Page:** 1

<div class="post-metadata">

### Author: ![lizzardguki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lizzardguki/32/103637_2.png) [@lizzardguki](https://discourse.nodered.org/u/lizzardguki)
#### Post date: [23 May 2022 10:51 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/1 "2022-05-23T10:51:48Z")

</div>

I have a basic OAuth flow to authenticate with 3rd party API , after the authentication is successful, I use a delay node to wait for x seconds (expires\_in property - 100 seconds) and then I push the message to refresh the token, and I am trying to keep that loop going, but after a couple of token refreshes, the node-red fails to authenticate. Is there any better way to make the flow?

 ![image](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/6/4/645da267561d01b2bd3699b07bfb07ee7a7c07f2.png)

---

<div class="post-metadata">

### Author: ![lu4t](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lu4t/32/32276_2.png) [@lu4t](https://discourse.nodered.org/u/lu4t)
#### Post date: [23 May 2022 12:26 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/2 "2022-05-23T12:26:44Z")

</div>

does the token tell you when is it expiring? is it a jwt?

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [23 May 2022 12:34 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/3 "2022-05-23T12:34:04Z")

</div>

Also, is it a public API, can you share?

---

<div class="post-metadata">

### Author: ![lizzardguki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lizzardguki/32/103637_2.png) [@lizzardguki](https://discourse.nodered.org/u/lizzardguki)
#### Post date: [23 May 2022 12:35 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/4 "2022-05-23T12:35:36Z")

</div>

Yeah it does.

---

<div class="post-metadata">

### Author: ![lizzardguki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lizzardguki/32/103637_2.png) [@lizzardguki](https://discourse.nodered.org/u/lizzardguki)
#### Post date: [23 May 2022 12:35 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/5 "2022-05-23T12:35:50Z")

</div>

Yes, its Airthings API

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [23 May 2022 12:43 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/6 "2022-05-23T12:43:57Z")

</div>

> [@lizzardguki](#):
>
> Airthings API

Are you sure you aren't exceeding the 120 requests per hour limit?

---

<div class="post-metadata">

### Author: ![lizzardguki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lizzardguki/32/103637_2.png) [@lizzardguki](https://discourse.nodered.org/u/lizzardguki)
#### Post date: [23 May 2022 12:49 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/7 "2022-05-23T12:49:33Z")

</div>

Probably, have too much organizations and around 900 sensors that i try to get latest data upon authentication. I have added delays so node-red won't hang but i think that may causing the problems.

---

<div class="post-metadata">

### Author: ![TotallyInformation](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/totallyinformation/32/31_2.png) [@TotallyInformation](https://discourse.nodered.org/u/TotallyInformation)
#### Post date: [23 May 2022 16:40 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/8 "2022-05-23T16:40:56Z")

</div>

Then you need a business account I think.

---

<div class="post-metadata">

### Author: ![lu4t](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lu4t/32/32276_2.png) [@lu4t](https://discourse.nodered.org/u/lu4t)
#### Post date: [23 May 2022 18:12 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/9 "2022-05-23T18:12:19Z")

</div>

then what's the point of refreshing the token continuously?.  
Why don't you just wait till it's about to expire and ask for a new one?

---

<div class="post-metadata">

### Author: ![lizzardguki](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/lizzardguki/32/103637_2.png) [@lizzardguki](https://discourse.nodered.org/u/lizzardguki)
#### Post date: [23 May 2022 19:13 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/10 "2022-05-23T19:13:25Z")

</div>

In addition to Airthings Webhook, we also scrape data every 7 days as a way of precautions, and push the data to an Influx database.  
We use data from API such as sensor name, location, organization to pass it along with webhook live data.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)
#### Post date: [22 July 2022 19:13 UTC](https://discourse.nodered.org/t/oauth-refresh-token-best-workflow/62962/11 "2022-07-22T19:13:48Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
