Tessera docs

Launch Tessera

Launch

Authentication

Refresh token

Exchange a refresh token for a new access token without signing in again.

POST

/v1/auth/refresh

Returns a new access token and rotates the refresh token. The old refresh token stops working immediately.

Request body

refresh_tokenstringrequired

The refresh token from Create token or a previous refresh.

device_idstringoptional

Optional device identifier, used to scope the session.

Response fields

access_tokenstringrequired

New JWT valid for 15 minutes.

refresh_tokenstringrequired

The rotated refresh token. Store it and discard the old one.

expires_inintegerrequired

Seconds until the access token expires.

Errors

401invalid_refresh_token

The refresh token is expired, revoked or already used.

429rate_limited

Too many requests. Retry after the number of seconds in Retry-After.

curl --request POST \  --url https://api.tessera.dev/v1/auth/refresh \  --header "Content-Type: application/json" \  --data '{"refresh_token":"rt_9Xk2mP4qLw8"}'
{  "access_token": "eyJhbGciOiJIUzI1NiIs…",  "refresh_token": "rt_4Hn7vB1sQz2",  "expires_in": 900}

© 2026 Tessera, Inc.

Support

Status

Create a free website with Framer, the website builder loved by startups, designers and agencies.