Refresh and disconnect
Synchronize over time, rotate tokens safely, and handle revoked connections.
Optional offline access
Request library:read offline_access during authorization if ongoing synchronization is necessary. Users can decline offline access while approving library access. Always check whether the token response contains a refresh token.
Access tokens last 15 minutes. Refresh tokens last 30 days and rotate after a successful refresh. Neither lifetime guarantees access: the app, user, developer account, consent, and authorizing Comick session must still be eligible.
Refresh an access token
For a public client:
curl --request POST 'https://comick.dev/api/auth/oauth2/token' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'grant_type=refresh_token' \
--data-urlencode 'client_id=YOUR_PUBLIC_CLIENT_ID' \
--data-urlencode 'refresh_token=CURRENT_REFRESH_TOKEN' \
--data-urlencode 'resource=https://api.comick.dev/integrations/v1'A confidential client instead authenticates with HTTP Basic using its current client ID and secret, as in the backend quickstart. Browser clients must omit cookies.
Handle rotation safely
Allow only one refresh request at a time per connection, including across backend workers. After success, atomically replace the stored access token, expiry, granted scope, and refresh token.
The old refresh token becomes invalid immediately. There is no reuse grace period; reusing an old token can revoke the token family. Do not automatically retry refresh after an ambiguous network failure. If the replacement token was lost, ask the user to reconnect.
For a failed API call, refresh at most once when appropriate, then retry the original read once. Handle invalid_grant or other permanent authorization failures by stopping synchronization and offering “Reconnect Comick.”
Revoke a token
Send a form-encoded request to the revocation endpoint. For a public client:
curl --request POST 'https://comick.dev/api/auth/oauth2/revoke' \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data-urlencode 'client_id=YOUR_PUBLIC_CLIENT_ID' \
--data-urlencode 'token=TOKEN_TO_REVOKE' \
--data-urlencode 'token_type_hint=refresh_token'Confidential clients use HTTP Basic authentication. To revoke an access token, use token_type_hint=access_token. When disconnecting from your own app, revoke each credential you hold and erase the locally stored tokens and cached user data according to your app's policy. Revoking an individual token is separate from removing all app consent.
User-controlled disconnection
Users can open Connected apps on Comick and disconnect your app. This removes consent and revokes its access and refresh tokens for that user, including outstanding authorizations.
Signing out, expiry, or revocation of the Comick session that authorized the connection also ends access. Account deletion, account-security revocation, loss of eligibility, or app suspension can end it earlier. Offline access does not survive those conditions. Stop background jobs when access ends and reconnect only after a user action.