I’m a bit confused to how all this works.
I’ve implemented Sign In with Apple in my native iOS app, I do save all info Apple provides once the login success, like IdentityToken, UserId, and authorization code.
Already reviewed and we have to implement the Revoke Tokens API endpoint using the Sign in with Apple REST API Revoke Tokens just that I don't have clear which the client_id, what is the client_secret, and what is the token.
As per my understanding.
Is client_id the bundle ID right?
Is client_secret the identityToken provided by Apple during the Sign In process?.. I just stored and share this token to our server but getting the invalid_client error
I'd really appreciate it if someone can explain what should I do with the info provided during Sign in with Apple flow (UserId, IdentityToken, and AuthorizationCode) in order to properly implement the Revoke Tokens API.