AuthService · AuthService_RefreshToken
Access
Available without an access token for account/bootstrap flows, including on private instances. The operation still validates its own credentials or cookie when required.
An intentionally empty body
Send {} as the JSON request body and the refresh cookie previously set by SignIn. RefreshTokenRequest has no fields because the credential is read from the cookie. A successful refresh rotates that stored session and returns a new accessToken and expiresAt; preserve the new Set-Cookie value. A revoked, expired or missing refresh cookie fails authentication.
Request
RefreshToken exchanges a valid refresh token for a new access token. The refresh token is read from the HttpOnly cookie. Returns a new short-lived access token.
/api/v1/auth/refreshParameters
No path or query parameters are declared.
Request body
Required
application/json · RefreshTokenRequest
Responses
200 · OK
application/json · RefreshTokenResponse
default · Default error response
application/json · Status
Complete operation definition
All declared constraints, media types and response details are retained below. Schema references link to their complete definitions.
Open JSON definition
{
"tags": [
"AuthService"
],
"description": "RefreshToken exchanges a valid refresh token for a new access token.\n The refresh token is read from the HttpOnly cookie.\n Returns a new short-lived access token.",
"operationId": "AuthService_RefreshToken",
"requestBody": {
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/RefreshTokenRequest"
}
}
},
"required": true
},
"responses": {
"200": {
"description": "OK",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/RefreshTokenResponse"
}
}
}
},
"default": {
"description": "Default error response",
"content": {
"application/json": {
"schema": {
"$ref": "#/components/schemas/Status"
}
}
}
}
}
}