Apple does not provide a /userinfo call like every other oAuth implementation I can think of... Providing the /userinfo call would solve the issue. You need to make this call to ensure the token is still valid from time to time. Also most other oAuth implementations provide a picture as well.