Graph API requests using an appsecret_proof that only contains the access token and app secret have been working fine since (at least) 2023. However in reviewing the docs (https://developers.facebook.com/docs/facebook-login/security/#appsecret) the inclusion of a time stamp inside the appsecret_proof as well as in a separate header, appsecret_time, is also indicated.
Is it required (now or soon) to include the time stamp?

Tag:-

Add a new comment.