OAuth oauth.net

Refresh Token

A refresh token is a long-lived credential that clients use to obtain new access tokens when the current one expires — without requiring the user to re-authorize.

When to use this Refresh tokens are issued alongside access tokens in the Authorization Code flow. Use them to silently renew access tokens in the background so users stay logged in across sessions. Not all authorization servers issue refresh tokens to every client type — public clients (SPAs, mobile apps) may receive rotating refresh tokens, and some deployments restrict refresh tokens to confidential clients only.

Access tokens are intentionally short-lived. When one expires, the client presents the refresh token to the token endpoint with grant_type=refresh_token and receives a new access token — and often a new refresh token — without any user interaction. The original refresh token should be discarded after use if a new one is returned.

Refresh tokens represent long-term delegated access and should be stored securely. If a refresh token is compromised, an attacker can maintain access until it's revoked. Authorization servers may implement refresh token rotation (issuing a new refresh token on every use and invalidating the previous one) to detect token theft.

More resources