Validity Period of Credentials and Tokens

The following specifications apply to OAuth2 in the HIN system:

TypeValidity
Auth Code10 minutes
Refresh TokenDuration of Access Token + 7 days
Access TokenVaries depending on the application (token group), typically 30-120 days
Client Secret (Client Credentials Flow)Valid for 1 year
API CallsMaximum 3 requests per second