Skip to content

Refresh an access token

POST
/v1/auth/refresh
curl --request POST \
--url http://localhost:8080/v1/auth/refresh \
--header 'Content-Type: application/json' \
--data '{ "refreshToken": "example" }'

Anonymous; the refresh token is the credential. Rotates it: the presented token is revoked and a new access/refresh pair is returned. Presenting a token that was already rotated is treated as theft; every refresh token of that user is revoked and the call fails with 401. 401 also when the token is unknown or expired or the user is inactive.

Media typeapplication/json
object
refreshToken
string
Examplegenerated
{
"refreshToken": "example"
}

OK

Media typeapplication/json

Access token (15 min default) + rotating refresh token, returned in the body and held in memory by the SPA.

object
accessToken
required
string
accessExpiresAt
required
string format: date-time
refreshToken
required
string
refreshExpiresAt
required
string format: date-time
user
required
object
id
required
string format: uuid
email
required
string
displayName
required
string
roles
required
Array<string>
isActive
required
boolean
lastLoginAt
required
null | string format: date-time
totpEnrolled
required
boolean
Examplegenerated
{
"accessToken": "example",
"accessExpiresAt": "2026-04-15T12:00:00Z",
"refreshToken": "example",
"refreshExpiresAt": "2026-04-15T12:00:00Z",
"user": {
"id": "2489E9AD-2EE2-8E00-8EC9-32D5F69181C0",
"email": "example",
"displayName": "example",
"roles": [
"example"
],
"isActive": true,
"lastLoginAt": "2026-04-15T12:00:00Z",
"totpEnrolled": true
}
}