The library should also support refresh tokens. Then the server can verify the user is still valid up to once per day. See: [https://developer.apple.com/documentation/signinwithapplerestapi/verifying_a_user]()