ParentFull thread0x1ceb00da·So a refresh token on its own isn't more secure than a simple api key. You need a lot of plumbing and abuse detection analytics around it as well.View on HN