A nifty refresh-token trick

Tim Bray, who works on the Google Identity team, documents here a pretty cool trick you can do (in a very specific scenario) to check if someone still is part of an organisation by using OAuth 2.0 refresh tokens

OAuth and API Consultation

