# Disable Refresh Token for Service Accounts

**URL:** <https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255>\
**Category:** Securing applications\
**Tags:** oidc\
**Created:** [February 13, 2020, 3:45pm UTC](https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255 "2020-02-13T15:45:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![justin.spies](https://avatars.discourse-cdn.com/v4/letter/j/dec6dc/32.png) [@justin.spies](https://forum.keycloak.org/u/justin.spies)\
**Post date:** [February 13, 2020, 3:45pm UTC](https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255/1 "2020-02-13T15:45:23Z")

</div>

We’d like to disable the inclusion of the refresh token in the authentication response when using the client\_credentials grant type for a service account. If I understand correctly there is a bit of conflict between the OAUTH2 spec (see [https://tools.ietf.org/html/rfc6749#section-4.4.3](https://tools.ietf.org/html/rfc6749#section-4.4.3), the refresh token should not be included in the response for a client\_credentials grant type) and the OIDC offline access spec (see [https://openid.net/specs/openid-connect-core-1\_0.html#OfflineAccess](https://openid.net/specs/openid-connect-core-1_0.html#OfflineAccess), it lists the refresh token should be returned but only when using offline\_access scope).

Is there a way to disable offline access / refresh tokens for a service account?

---

<div class="post-metadata">

**Author:** ![blackjackyau](https://avatars.discourse-cdn.com/v4/letter/b/838e76/32.png) [@blackjackyau](https://forum.keycloak.org/u/blackjackyau)\
**Post date:** [March 18, 2020, 5:59am UTC](https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255/2 "2020-03-18T05:59:02Z")

</div>

looking at the same issue as well  
in my case i am using a public client with SPA application  
and I have disabled offline access grant as well …  
and refresh token still returning from the auth code grant

---

<div class="post-metadata">

**Author:** ![werjo](https://avatars.discourse-cdn.com/v4/letter/w/a698b9/32.png) [@werjo](https://forum.keycloak.org/u/werjo)\
**Post date:** [April 23, 2020, 7:20am UTC](https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255/3 "2020-04-23T07:20:12Z")

</div>

Same Problem here.I also deisbaled offlice\_access in the client and the generated service account. But the refresh token is still in the response.

---

<div class="post-metadata">

**Author:** ![juliaaano](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/juliaaano/32/1255_2.png) [@juliaaano](https://forum.keycloak.org/u/juliaaano)\
**Post date:** [August 18, 2020, 1:27am UTC](https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255/4 "2020-08-18T01:27:32Z")

</div>

From my research, I found many other similar enquires and my conclusion is that I don’t think it is possible to disable the refresh token. I say “I think” because nobody with the authority has never showed up and confirmed.

At same time, I think this can be a significant security risk depending on the architecture in place.

---

<div class="post-metadata">

**Author:** ![reste85](https://avatars.discourse-cdn.com/v4/letter/r/898d66/32.png) [@reste85](https://forum.keycloak.org/u/reste85)\
**Post date:** [December 4, 2020, 1:11pm UTC](https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255/5 "2020-12-04T13:11:00Z")

</div>

UP.  
We faced this issue also on our side.  
As stated by justin.spies, the RFC clearly states that “the refresh token should not be included in the response for a client\_credentials grant type”.  
Can someone from RedHat team explain why is currently included?

Thanks a lot!

---

<div class="post-metadata">

**Author:** ![Tr4L](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/tr4l/32/3148_2.png) [@Tr4L](https://forum.keycloak.org/u/Tr4L)\
**Post date:** [May 18, 2021, 9:00am UTC](https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255/6 "2021-05-18T09:00:41Z")

</div>

Hi,

This seems to be a bit of misunderstanding here.

The offline access scope give you a refresh token without any expiration date.  
The refresh token you got without this scope will have an expiration and can be configured on the admin console.

---

<div class="post-metadata">

**Author:** ![AnirudhaGohokar](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/anirudhagohokar/32/5811_2.png) [@AnirudhaGohokar](https://forum.keycloak.org/u/AnirudhaGohokar)\
**Post date:** [May 13, 2022, 4:49am UTC](https://forum.keycloak.org/t/disable-refresh-token-for-service-accounts/1255/8 "2022-05-13T04:49:45Z")

</div>

This clearly diverts from keycloaks client credential grant flow documented [here](https://github.com/keycloak/keycloak-documentation/blob/main/server_admin/topics/clients/oidc/service-accounts.adoc). Either update the document or need to fix the issue by removing refresh token.
