OAuth errors
The token and revocation endpoints answer errors as JSON:?error=...&error_description=...&state=..., except when client_id or redirect_uri is wrong: those stay on a Drime page.
API errors
Checking that a token still works
CallGET /api/v1/users/me. Every token can read it, whatever its scopes, and it answers 401 as soon as the token stops working.
When tokens stop working early
An access token lasts one hour, but it can stop working sooner, without warning:- you refreshed it: each refresh retires the access token you had;
- the user disconnected your application from Devices & apps in their Drime settings;
- you called
/oauth/revoke; - a refresh token was presented twice. Drime treats it as stolen and revokes every token your application holds for that user;
- an authorization code was used twice, and the tokens it produced are revoked;
- Drime suspended your application, or you deleted it.
401 by refreshing once. If the refresh answers invalid_grant, the user has to authorize your application again.
Rate limits
Beyond a limit, Drime answers
429. Wait, then retry with an increasing delay.