Empresas
Empregos
  • Sobre nós
  • Soluções
    • Publicação de vagas
      Publique sua vaga e receba candidatos qualificados em 48h.
    • Avaliações de candidatos
      Mais de 500 testes técnicos e psicológicos, mais anti-fraude.
    • Headhunting
      Busca executiva personalizada do início ao fim.
    • Folha de Pagamento + EOR
      Dispersão de folha e EOR em mais de 15 países da LATAM.
  • Preços
  • Empregos

0

70
Visualizações
Storing Access & Refresh tokens from multiple Providers?

Say I am allowing my users to connect to Facebook, Instagram, Pinterest & Twitter, so they can use their API's. So I get access tokens for all those providers.

From what I've read, my inclination now is to store them in a http-only cookie.

However, with 4 access tokens, would that mean that all 4 access tokens are always being sent on every request?

What would be a secure approach here? Or would I in this case not store them on the client at all?

about 4 years ago · Juan Pablo Isaza
1 Respostas
Responde à pergunta

0

It depends on the exact architecture of your solution. If you have a backend, and your backend calls these APIs then you can keep those tokens in your backend. They don't have to be kept in the front-end at all. If your front-end needs those tokens (e.g. it is calling these APIs directly), then you have to keep the tokens there, and they have to be readable by your frontend app (so they can't be stored in an HTTP-only cookie).

I would struggle not to have any tokens in the browser. It's best to keep them in the backend.

about 4 years ago · Juan Pablo Isaza Relatório
Responde à pergunta
Encontrar trabalhos remotos

Descubra a nova forma de encontrar um emprego!

melhores empregos
Principais categorias de trabalho
Empresas
Postar vaga Preços Comercial
Jurídico
Termos e Condições Política de privacidade
© 2026 PeakU Inc. All Rights Reserved.
Andres GPT
Recomende algumas ofertas para mim
Preciso de ajuda