Skip to main content
POST
Rotate the refresh token and get a new access token

Authorizations

x-api-key
string
header
required

Body

application/json
refreshToken
string
required

The current refresh token.

Response

New access token and rotated refresh token.

Access token plus rotating refresh token, returned identically by access_refresh verify and by refresh.

authMode
enum<string>
required
Available options:
access_refresh
accessToken
string
required

JWT to send in the Authorization Bearer header. Expires 15 minutes after issue.

refreshToken
string
required

Opaque token used to obtain a new access token. Rotates on every /auth/refresh call.

expiresAt
string<date-time>
required

ISO 8601 timestamp when accessToken expires.

tokenType
enum<string>
required
Available options:
Bearer