MobiariDocs

Refresh a session

POST
/auth/refresh

Trades a refresh token for a new access token and a new refresh token. The presented refresh token stops working (rotation), so keep only the newest one and do not send two refreshes with the same token.

If the response to a refresh is lost, retrying with the same token within 30 seconds is safe: a fresh pair is issued and the one the client never received is retired. Otherwise, presenting a refresh token that was already used signs the whole session out on every device holding it (refresh_token_reused). A token whose session ended (sign-out, device revoked, password changed) or expired is invalid_refresh_token. Both mean: sign in again.

Header Parameters

Idempotency-Key?string

A unique value (e.g. a UUID) per logical request. Retrying with the same key within 24 hours replays the first response instead of repeating the side effect; the replay carries Idempotent-Replayed: true. Reusing a key for a different request is a 422 idempotency_key_reused; retrying while the first is still running is a 409 idempotency_request_in_progress. JSON bodies up to 1 MB.

Lengthlength <= 255

Request Body

application/json

TypeScript Definitions

Use the request body type in TypeScript.

refresh_token*string

The refresh token from the last sign-in or refresh.

Response Body

application/json

application/json

application/json

application/json

curl -X POST "https://example.com/auth/refresh" \  -H "Content-Type: application/json" \  -d '{    "refresh_token": "string"  }'
{
  "expires_in": 86400,
  "refresh_token": "string",
  "refresh_token_expires_in": 2592000,
  "session_id": "1ffd059c-17ea-40a8-8aef-70fd0307db82",
  "token": "string",
  "token_type": "Bearer",
  "user": {
    "created_at": "2019-08-24T14:15:22Z",
    "email": "string",
    "full_name": "string",
    "id": "497f6eca-6276-4993-bfeb-53cbbbba6f08",
    "is_active": true,
    "locale": null,
    "phone": "string",
    "totp_enabled": true,
    "whatsapp_2fa_enabled": true
  }
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}
{
  "code": "not_found",
  "details": {},
  "error": "Order not found"
}