Refresh OAuth access token
curl --request POST \
--url https://api.example.com/oauth/token/refresh \
--header 'Content-Type: application/json' \
--data '
{
"refreshToken": "rt_abc123xyz..."
}
'import requests
url = "https://api.example.com/oauth/token/refresh"
payload = { "refreshToken": "rt_abc123xyz..." }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({refreshToken: 'rt_abc123xyz...'})
};
fetch('https://api.example.com/oauth/token/refresh', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/oauth/token/refresh",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'refreshToken' => 'rt_abc123xyz...'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/oauth/token/refresh"
payload := strings.NewReader("{\n \"refreshToken\": \"rt_abc123xyz...\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/oauth/token/refresh")
.header("Content-Type", "application/json")
.body("{\n \"refreshToken\": \"rt_abc123xyz...\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/oauth/token/refresh")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"refreshToken\": \"rt_abc123xyz...\"\n}"
response = http.request(request)
puts response.read_bodyOAuth
Refresh OAuth Token
🔓 PUBLIC ENDPOINT: Exchanges a refresh token for a new access token and refresh token pair. The old refresh token is automatically revoked. Rate limit: 20 requests per minute.
POST
/
oauth
/
token
/
refresh
Refresh OAuth access token
curl --request POST \
--url https://api.example.com/oauth/token/refresh \
--header 'Content-Type: application/json' \
--data '
{
"refreshToken": "rt_abc123xyz..."
}
'import requests
url = "https://api.example.com/oauth/token/refresh"
payload = { "refreshToken": "rt_abc123xyz..." }
headers = {"Content-Type": "application/json"}
response = requests.post(url, json=payload, headers=headers)
print(response.text)const options = {
method: 'POST',
headers: {'Content-Type': 'application/json'},
body: JSON.stringify({refreshToken: 'rt_abc123xyz...'})
};
fetch('https://api.example.com/oauth/token/refresh', options)
.then(res => res.json())
.then(res => console.log(res))
.catch(err => console.error(err));<?php
$curl = curl_init();
curl_setopt_array($curl, [
CURLOPT_URL => "https://api.example.com/oauth/token/refresh",
CURLOPT_RETURNTRANSFER => true,
CURLOPT_ENCODING => "",
CURLOPT_MAXREDIRS => 10,
CURLOPT_TIMEOUT => 30,
CURLOPT_HTTP_VERSION => CURL_HTTP_VERSION_1_1,
CURLOPT_CUSTOMREQUEST => "POST",
CURLOPT_POSTFIELDS => json_encode([
'refreshToken' => 'rt_abc123xyz...'
]),
CURLOPT_HTTPHEADER => [
"Content-Type: application/json"
],
]);
$response = curl_exec($curl);
$err = curl_error($curl);
curl_close($curl);
if ($err) {
echo "cURL Error #:" . $err;
} else {
echo $response;
}package main
import (
"fmt"
"strings"
"net/http"
"io"
)
func main() {
url := "https://api.example.com/oauth/token/refresh"
payload := strings.NewReader("{\n \"refreshToken\": \"rt_abc123xyz...\"\n}")
req, _ := http.NewRequest("POST", url, payload)
req.Header.Add("Content-Type", "application/json")
res, _ := http.DefaultClient.Do(req)
defer res.Body.Close()
body, _ := io.ReadAll(res.Body)
fmt.Println(string(body))
}HttpResponse<String> response = Unirest.post("https://api.example.com/oauth/token/refresh")
.header("Content-Type", "application/json")
.body("{\n \"refreshToken\": \"rt_abc123xyz...\"\n}")
.asString();require 'uri'
require 'net/http'
url = URI("https://api.example.com/oauth/token/refresh")
http = Net::HTTP.new(url.host, url.port)
http.use_ssl = true
request = Net::HTTP::Post.new(url)
request["Content-Type"] = 'application/json'
request.body = "{\n \"refreshToken\": \"rt_abc123xyz...\"\n}"
response = http.request(request)
puts response.read_bodyExchanges a refresh token for a new access token and refresh token pair. The old refresh token is automatically revoked.
This is a PUBLIC ENDPOINT (no authentication required). Rate-limited to
20 requests per minute.
Request Body
| Field | Type | Required | Description |
|---|---|---|---|
refreshToken | string | Yes | Refresh token from token generation |
Example Request
curl -X POST https://api.timbrix.mx/oauth/token/refresh \
-H "Content-Type: application/json" \
-d '{
"refreshToken": "rt_abc123xyz..."
}'
import { Timbrix } from "@timbrix/sdk"
const client = new Timbrix()
const tokens = await client.oauth.refreshToken({
refreshToken: "rt_abc123xyz...",
})
console.log(tokens.access_token, tokens.refresh_token)
Example Response
{
"access_token": "eyJhbGciOiJIUzI1NiIs...",
"refresh_token": "rt_new_refresh_token...",
"token_type": "Bearer",
"expires_in": 3600,
"scope": "read:user read:organization"
}
Token Rotation
When you refresh a token:- Old refresh token is immediately revoked
- New access token and refresh token are issued
- Use the new refresh token for future refreshes
- Old refresh token cannot be reused
Best Practices
- Refresh tokens before they expire
- Store new refresh tokens securely
- Handle token refresh errors gracefully
- Implement automatic token refresh in your client
Common Errors
400 Bad Request
Invalid request. Refresh token is required.401 Unauthorized
Invalid or expired refresh token. The refresh token may have been used already or has expired.429 Too Many Requests
Rate limit exceeded. Maximum 20 requests per minute for token refresh.Body
application/json
Refresh token obtained from token generation
Example:
"rt_abc123xyz..."
Response
Token refreshed successfully. Returns new access_token, refresh_token, token_type (Bearer), expiration time, and scopes.