Contents

Security › Authentication & Authorization

Refresh Token

A long-lived credential used only to get new short-lived access tokens without logging in again.

Short-lived access tokens limit the damage of a leak, but nobody wants to log in every 15 minutes. The fix is two tokens:

Access tokenRefresh token
LifetimeMinutes (e.g. 15 min)Days to months
Sent toEvery API callOnly the token endpoint
UsuallyA JWT, verified without lookupOpaque, stored and checked in the DB

The flow:

  1. Login returns both tokens.
  2. The client calls APIs with the access token.
  3. When the access token expires (API returns 401), the client sends the refresh token to POST /auth/refresh and gets a new access token.
  4. On logout, the server deletes the refresh token. Within minutes, every access token it could produce has expired too.

Why it helps

The refresh token is sent rarely and to one endpoint, so it’s exposed far less. And because the server stores it, you get back the ability to revoke a session, which pure JWTs lack.

Where to keep it

  • Browsers: an HttpOnly, Secure cookie, scoped to the refresh path. Not localStorage, where any XSS can read it.
  • Mobile: the OS keychain / keystore.

If a refresh token is stolen, the attacker can mint access tokens for its whole lifetime. Refresh token rotation is the standard defense.