Short answer
HubSpot's developer blog: the access token expires (it uses 30 minutes in its example), and expires_in tells you when. Refresh before calls fail with a 401, by POSTing to the OAuth token endpoint, and always keep the latest refresh token returned. Never cache refresh tokens or client secrets in a general-purpose cache.
1. Rules
- Read
expires_infrom every token response. - Refresh slightly early rather than on error.
- Store refresh tokens and secrets like passwords.
2. Credentials
See client ID and secret.
3. Related
Service keys for data-only integrations.