Security › Authentication & Authorization
Refresh Token
A long-lived credential used only to get new short-lived access tokens without logging in again.
Short-lived access tokens limit the damage of a leak, but nobody wants to log in every 15 minutes. The fix is two tokens:
| Access token | Refresh token | |
|---|---|---|
| Lifetime | Minutes (e.g. 15 min) | Days to months |
| Sent to | Every API call | Only the token endpoint |
| Usually | A JWT, verified without lookup | Opaque, stored and checked in the DB |
The flow:
- Login returns both tokens.
- The client calls APIs with the access token.
- When the access token expires (API returns 401), the client sends
the refresh token to
POST /auth/refreshand gets a new access token. - On logout, the server deletes the refresh token. Within minutes, every access token it could produce has expired too.
Why it helps
The refresh token is sent rarely and to one endpoint, so it’s exposed far less. And because the server stores it, you get back the ability to revoke a session, which pure JWTs lack.
Where to keep it
- Browsers: an
HttpOnly,Securecookie, scoped to the refresh path. NotlocalStorage, where any XSS can read it. - Mobile: the OS keychain / keystore.
If a refresh token is stolen, the attacker can mint access tokens for its whole lifetime. Refresh token rotation is the standard defense.