question

brokenoval avatar image
brokenoval asked sam Deactivated commented

What are the rules around access_tokens and expiry?

There's a couple of answers that explain that access_tokens expire after a year. And there is another question which indicates that tokens can be black listed individually if suspicious activity is detected.

I have been playing around with our merchant, specifically with push notifications, and I've found a couple of times today that tokens have expired within about an hour. I'm wondering are there any other rules that could be invalidating tokens that haven't been documented yet?

Specifically:

  1. What corresponds to "suspicious activity"? (burst rates etc) see: https://devask.clover.com/question/42...
  2. Is there a limit on the number of tokens that can be live for a merchant?
  3. Token's are merchant specific and app specific. Are they app version specific?

EDIT:

  1. We've noticed tokens expiring every day for us - if you uninstall and reinstall an app - will the old token still be valid, or is it unset by an uninstall?
  2. Is there a process for requesting rate limits on a case by case basis?
  3. What effect do permissions and modules have on the access_tokens

Thanks!

10 |2000

Up to 2 attachments (including images) can be used with a maximum of 512.0 KiB each and 1.0 MiB total.

0 Answers

Welcome to the
Clover Developer Community