Skip to main content
Question

Removing app does not revoke refresh token

  • May 22, 2025
  • 1 reply
  • 15 views

Forum|alt.badge.img

After removing a custom app from my user account, I can still use the refresh token and access everything. Essentially, removing an app does not revoke permissions. Why? This is a huge security concern.

1 reply

Forum|alt.badge.img

Hi, 

Can you send me the client id of that application or the enterprise id the app is tied to? It looks like the account that posted this question is not tied to an enterprise.

Thanks, 

Alex, Box Developer Advocate