---
title: "Refresh access token"
method: POST
path: "/token"
tags: ["session"]
---

# Refresh access token

`POST /token`

Generate a new JWT access token using a valid refresh token. The refresh token used will be revoked and a new one will be issued.

## Request body

- RefreshTokenRequest — Request to refresh an access token
  - `refreshToken` string, required — Refresh token used to generate a new access token

## Response `200`

Access token successfully refreshed

- Session — User authentication session containing tokens and user information
  - `accessToken` string, required — JWT token for authenticating API requests
  - `accessTokenExpiresIn` integer, required — Expiration time of the access token in seconds
  - `refreshTokenId` string, required — Identifier for the refresh token
  - `refreshToken` string, required — Token used to refresh the access token
  - `user` User — User profile and account information
    - `avatarUrl` string, required — URL to the user's profile picture
    - `createdAt` string, date-time, required — Timestamp when the user account was created
    - `defaultRole` string, required — Default authorization role for the user
    - `displayName` string, required — User's display name
    - `email` string, email — User's email address
    - `emailVerified` boolean, required — Whether the user's email has been verified
    - `id` string, required — Unique identifier for the user
    - `isAnonymous` boolean, required — Whether this is an anonymous user account
    - `locale` string, required — User's preferred locale (language code)
    - `metadata` object, required — Custom metadata associated with the user
    - `phoneNumber` string — User's phone number
    - `phoneNumberVerified` boolean, required — Whether the user's phone number has been verified
    - `roles` string[], required — List of roles assigned to the user
    - `activeMfaType` string, nullable — Active MFA type for the user

## Other responses

- `default` — An error occurred while processing the request

---

[API](https://skmtc.net/nhost/apis/nhost-authentication-api.md) · [All operations](https://skmtc.net/nhost/apis/nhost-authentication-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/nhost/nhost-authentication-api/revisions/a5c0d88b55c4/schema)
