Beyond the login redirect, developers rebuild the whole token lifecycle — refresh rotation races, Apple's hand-signed secrets, and per-provider quirks top the complaints
Asked:
“What OAuth 2.0 / OpenID Connect client plumbing do developers complain about hand-writing or re-implementing per provider — token refresh rotation, PKCE, provider-specific quirks (Apple, Microsoft, Google), session and revocation handling? Find specific GitHub issues, Reddit threads, and Stack Overflow questions with URLs and short quotes.”
An illustrative web scan, not a prevalence survey: 32 source-linked complaints and questions drawn evenly from three developer communities — GitHub issues, Reddit threads, and Stack Overflow questions (Reddit appears under two hostnames but counts as one platform; 16 of 32 rows). Each row carries a verified short quote; a few Stack Overflow URLs are alternate forms of the same underlying question and are flagged as grouped variants, not independent corroboration.
Where the pain concentrates: evidence matrix of plumbing clusters by community
Each square is one complaint or question. Hover or tap a square for the title and quote; click to open the source. Hollow squares are grouped URL variants of the same Stack Overflow question. Colour identifies the community.
Five of the eight GitHub issues ask for single-flight or grace-period refresh handling; one warns that until it lands in core, “every consumer… will need to roll their own pre-refresh sidecar.” github.com
The clearest cross-provider statement is a Stack Overflow question asking whether a “custom authorization flow implementation” is required for every IdP just to get refresh tokens to behave consistently. stackoverflow.com
Apple is the single most-complained-about provider here (7 of 32 rows): hand-generated ES256 client-secret JWTs, an undocumented form-encoding requirement — “Incredible that this is documented absolutely nowhere” — and opaque invalid_client errors. stackoverflow.com
Even developers paying for hosted auth still manage “Google's developer console, Apple's certificates, and Microsoft's Azure portal regardless” — the per-provider console work never goes away. reddit.com
All 32 complaints, with quotes and sources
Grouped by plumbing cluster. “Variant” marks alternate URLs of the same underlying Stack Overflow question.
Cluster
Community
Provider
Date
Quote
Source
Method: 32 complaint/question rows extracted from public GitHub issues, Reddit threads, and Stack Overflow questions (8 per hostname; reddit.com and www.reddit.com counted as one platform; no hostname exceeds 25% of rows), published 2019–2026, collected as an illustrative web scan rather than a prevalence survey. Each row records the source URL, a normalized plumbing topic, and a verified short quote; cluster labels were assigned editorially from topic and provider. Alternate Stack Overflow URLs of the same question are grouped, not counted as independent corroboration. Long quotes trimmed for space.