Skip to main content

OAuth errors

The token and revocation endpoints answer errors as JSON:
Errors on the authorization screen come back to your redirect URL as ?error=...&error_description=...&state=..., except when client_id or redirect_uri is wrong: those stay on a Drime page.

API errors

Checking that a token still works

Call GET /api/v1/users/me. Every token can read it, whatever its scopes, and it answers 401 as soon as the token stops working.

When tokens stop working early

An access token lasts one hour, but it can stop working sooner, without warning:
  • you refreshed it: each refresh retires the access token you had;
  • the user disconnected your application from Devices & apps in their Drime settings;
  • you called /oauth/revoke;
  • a refresh token was presented twice. Drime treats it as stolen and revokes every token your application holds for that user;
  • an authorization code was used twice, and the tokens it produced are revoked;
  • Drime suspended your application, or you deleted it.
Handle 401 by refreshing once. If the refresh answers invalid_grant, the user has to authorize your application again.

Rate limits

Beyond a limit, Drime answers 429. Wait, then retry with an increasing delay.