---
title: "Get a new auth token using a refresh token."
method: POST
path: "/refresh-token"
---

# Get a new auth token using a refresh token.

`POST /refresh-token`

## Request body

- RefreshToken
  - `refresh_token` string, required — The refresh token retrieved from an authentication endpoint.

## Response `200`

Refresh token response. If SECURITY_REFRESH_TOKEN_COOKIE_NAME is configured, the response will NOT include the refresh token. The refresh token will be stored in a cookie.

- JsonResponseWithToken
  - `meta` object, required
    - `code` integer, required — Http status code
  - `response` object, required
    - `user` object — By default an empty dictionary is returned. However by overriding _User::get_security_payload()_ any attributes of the User model can be returned.
      - `authentication_token` string — Token to be used in future token-based API calls. Note this only returned from those APIs that accept a 'include_auth_token' query param.
      - `refresh_token` string — A refresh token that can be used to get a new auth token. This is only returned if the application has enabled refresh tokens.
    - `csrf_token` string — Session CSRF token

## Other responses

- `400` — Errors while validating attributes.

---

[API](https://skmtc.net/pallets-eco/apis/flask-security-external-api.md) · [All operations](https://skmtc.net/pallets-eco/apis/flask-security-external-api/llms.txt) · [OpenAPI document](https://skmtc-service-staging.skmtc.workers.dev/v1/apis/pallets-eco/flask-security-external-api/versions/5ee7c28d6e1e/schema)
