Refresh Token
A refresh token is a long-lived credential that clients use to obtain new access tokens when the current one expires — without requiring the user to re-authorize.
Access tokens are intentionally short-lived. When one expires, the client presents the refresh token to the token endpoint with grant_type=refresh_token and receives a new access token — and often a new refresh token — without any user interaction. The original refresh token should be discarded after use if a new one is returned.
Refresh tokens represent long-term delegated access and should be stored securely. If a refresh token is compromised, an attacker can maintain access until it's revoked. Authorization servers may implement refresh token rotation (issuing a new refresh token on every use and invalidating the previous one) to detect token theft.
More resources
- Refresh Tokens overview
- Refreshing Access Tokens (oauth.com)
- Refresh Tokens: What they are and when to use them (auth0.com)