Refresh access token
Client
Refresh access token
Refresh access token using refresh token.
- Web clients: Use httpOnly refresh token cookie with X-CSRF-Token header
- Mobile/Desktop/Server clients: Send refreshToken in request body
POST
Refresh access token
Headers
CSRF token received from login/register response (required for web clients only)
Query Parameters
Client type determines how refresh tokens are handled:
- web: Refresh token from httpOnly cookie, requires X-CSRF-Token header
- mobile/desktop/server: refreshToken provided in request body, new refreshToken returned in response
Available options:
web, mobile, desktop, server Body
application/json
Refresh token (required for mobile/desktop/server clients only)