Authentication
Projects
Environments
Rows
Functions
Webhooks
Authentication
Refresh token
Exchange a refresh token for a new access token without signing in again.
POST
/v1/auth/refresh
Returns a new access token and rotates the refresh token. The old refresh token stops working immediately.
Request body
refresh_tokenstringrequiredThe refresh token from Create token or a previous refresh.
device_idstringoptionalOptional device identifier, used to scope the session.
Response fields
access_tokenstringrequiredNew JWT valid for 15 minutes.
refresh_tokenstringrequiredThe rotated refresh token. Store it and discard the old one.
expires_inintegerrequiredSeconds until the access token expires.
Errors
invalid_refresh_tokenThe refresh token is expired, revoked or already used.
rate_limitedToo many requests. Retry after the number of seconds in Retry-After.
© 2026 Tessera, Inc.
Support
Status