Is it possible to issue a Refresh Token based on client?
For example, client A and B are registered in the same realm and they both use client_credentials flow. When client A requests for access token, a refresh token will be issued. But for client B, no refresh token will be issued, only access token.
I am not sure if you can restrict like that from the same realm. But as an alternative approach you could set the Refresh Token Lifetime (seconds) for Client B to a negligible number like 1 second. This way even if a refresh token is issued, it expires really fast.