Refresh an access token
POST
/v1/auth/refresh
const url = 'http://localhost:8080/v1/auth/refresh';const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"refreshToken":"example"}'};
try { const response = await fetch(url, options); const data = await response.json(); console.log(data);} catch (error) { console.error(error);}curl --request POST \ --url http://localhost:8080/v1/auth/refresh \ --header 'Content-Type: application/json' \ --data '{ "refreshToken": "example" }'Anonymous; the refresh token is the credential. Rotates it: the presented token is revoked and a new access/refresh pair is returned. Presenting a token that was already rotated is treated as theft; every refresh token of that user is revoked and the call fails with 401. 401 also when the token is unknown or expired or the user is inactive.
Request Bodyrequired
Section titled “Request Bodyrequired”Media typeapplication/json
object
refreshToken
string
Examplegenerated
{ "refreshToken": "example"}Responses
Section titled “Responses”OK
Media typeapplication/json
Access token (15 min default) + rotating refresh token, returned in the body and held in memory by the SPA.
object
accessToken
required
string
accessExpiresAt
required
string format: date-time
refreshToken
required
string
refreshExpiresAt
required
string format: date-time
user
required
object
id
required
string format: uuid
email
required
string
displayName
required
string
roles
required
Array<string>
isActive
required
boolean
lastLoginAt
required
null | string format: date-time
totpEnrolled
required
boolean
Examplegenerated
{ "accessToken": "example", "accessExpiresAt": "2026-04-15T12:00:00Z", "refreshToken": "example", "refreshExpiresAt": "2026-04-15T12:00:00Z", "user": { "id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0", "email": "example", "displayName": "example", "roles": [ "example" ], "isActive": true, "lastLoginAt": "2026-04-15T12:00:00Z", "totpEnrolled": true }}