Skip to content
トレカクラウド
Esc
↑↓navigate↵open⌘Jpreview
On this page

Tokens and expiry

How long access and refresh tokens last, how to refresh them, and how to store them safely.

A partner API token proves that a shop member approved your app. If it leaks, someone else can read that shop’s data. Follow these rules.

Lifetimes

Token Lifetime Use
Access token 15 minutes from issue Send it as Authorization: Bearer on API calls
Refresh token 90 days from issue Exchange it for new tokens when the access token expires

Refresh tokens rotate: every refresh returns a new one, and the one you used stops working. As long as you refresh regularly, the connection keeps working past 90 days.

Refreshing

const response = await fetch(
  "https://api.toreca-cloud.com/api/auth/oauth2/token",
  {
    method: "POST",
    headers: {
      Authorization: "Basic " + basicCredentials,
      "Content-Type": "application/x-www-form-urlencoded",
    },
    body: new URLSearchParams({
      grant_type: "refresh_token",
      refresh_token: storedRefreshToken,
      resource: "https://api.toreca-cloud.com/partner/v1",
    }),
  },
);
const next = await response.json();
// Save next.refresh_token (the old one no longer works)
  • When the API answers 401, refresh and retry once.
  • Refresh at most once at a time per connection. Two parallel refreshes make one of them use a stale refresh token and fail.
  • Save the new refresh token as soon as you receive it. If saving fails, you can’t refresh again.
  • If refreshing fails with invalid_grant, ask a shop member to approve again.

Storing tokens

  • Keep tokens and the client secret on your server only. Never put them in a browser, a mobile app or a static site’s JavaScript.
  • Encrypt them at rest and limit who and what can read them.
  • Keep tokens out of logs, error reports and analytics.
  • If the client secret may have leaked, ask the shop admin to regenerate it (“Regenerate secret”). The old secret stops working at once.

When the connection stops

The API refuses calls in these cases even with an unexpired token.

Situation Response
The shop revoked the connection 403 connection_revoked
The shop or Toreca Cloud paused the app 403 client_disabled
The approving member left or lost a needed permission 403 forbidden
The token lacks the needed scope 403 insufficient_scope

To disconnect from your side, call DELETE /partner/v1/connection. It also revokes every refresh token your app holds for that shop.

Last updated on October 4, 2026

Was this page helpful?