Partner client systems should only invoke the /authenticate/token API once a token has become invalid for one of the above reasons. This will be evident by an HTTP response of 401 Unauthorized from ...