Network Reauthorization Cadences & Token Expiration
Table of Contents
Social networks issue access tokens that allow Sprout Social to publish content, retrieve messages, and pull analytics. Depending on the network's API policy, access tokens may expire periodically or remain active until an event (such as a password change or permission revocation) invalidates them.
Platform Token Expiration Reference
Instagram
Periodic Reauthorization: Every 90 days for standard/legacy reauthorization.
Notes: System User tokens do not require 90-day periodic reauthorization. Profiles may disconnect if login credentials or admin permissions are updated natively.
Facebook
Periodic Reauthorization: None (no fixed expiration date).
Notes: Profiles remain connected unless a native Facebook password is reset, two-factor authentication is changed, or the authorizing user loses admin access in Meta Business Manager.
LinkedIn
Periodic Reauthorization: Every 60 days (or up to 365 days depending on member authorization and token type).
Notes: LinkedIn requires periodic reauthorization to maintain API access. Members will receive reauthorization prompts in Sprout when a profile approaches token expiration.
X (Twitter)
Periodic Reauthorization: None.
Notes: Tokens do not expire automatically on a schedule. Disconnections occur if access is revoked in X account settings or if account security settings change.
TikTok
Periodic Reauthorization: Refresh tokens are valid for up to 365 days.
Notes: Sprout automatically refreshes short-term session tokens in the background. Manual reauthorization is only needed if the 365-day refresh window expires or access is revoked natively.
Pinterest
Periodic Reauthorization: Refresh tokens are valid for up to 1 year.
Notes: Tokens refresh automatically. Reauthorization is required only if access is revoked or after 1 year of continuous connection.
YouTube (Google)
Periodic Reauthorization: None.
Notes: Tokens remain connected indefinitely unless the connected Google Account password changes, access is revoked from Google Security settings, or 2FA settings change.
Threads
Periodic Reauthorization: None.
Notes: Follows Meta infrastructure rules. Tokens do not expire on a fixed schedule, but reauthorization is required if Meta password or admin access changes.
Bluesky
Periodic Reauthorization: None.
Notes: Uses App Passwords or OAuth sessions that remain active until app passwords are deleted or credentials change.
Google Business Profile
Periodic Reauthorization: None.
Notes: Access remains active unless the Google Account password is changed or permissions are revoked natively.
WhatsApp
Periodic Reauthorization: None.
Notes: Managed via Meta Business Manager / Cloud API. Reauthorization is required only if business access or system user permissions change.
Event-Based Disconnections vs. Periodic Expirations
If your profile disconnects outside of a scheduled token expiration window, it is typically caused by one of the following native network actions:
Password Reset: Changing your password on the native network immediately invalidates existing access tokens.
Permission or Admin Changes: If the user who originally connected the profile loses admin access or is removed from the native page/business account, Sprout loses access.
Security Checkpoints: Native networks may flag account activity for security verification, temporarily pausing third-party app connections until verified natively.
Frequently Asked Questions
How often do I need to reauthorize my social profiles in Sprout?
It depends on the network. Instagram (standard authentication) requires reauthorization every 90 days, and LinkedIn requires reauthorization every 60 to 365 days. Most other networks (such as Facebook, X, YouTube, and Google Business Profile) do not expire on a fixed schedule and only require reauthorization if credentials or permissions change.
Why did my profile disconnect if the token does not expire?
Even networks without scheduled token expirations will disconnect if a native password is updated, admin permissions are modified, or the network triggers a security checkpoint. Reauthorizing the profile in Sprout restores the connection immediately.
Was this article helpful?