Skip to main content

POST /api/userAuth/refresh-token

Issues a new access token using the current refresh token. The refresh token is automatically rotated — the old one is invalidated and a new one is issued.
Call this endpoint whenever you receive a 401 Unauthorized response on any other request. It is safe to call proactively when the access token is about to expire.

Required Header

x-api-key: your pk_live_… key.

Two Modes

Depending on your client type, you send the refresh token differently.

Web (browser)

The refresh token is stored in an HTTP-only cookie set during login. You do not need to read or send it manually — just include credentials: 'include' so the browser attaches the cookie automatically.

Mobile / non-browser

Include the refresh token in the x-refresh-token header, and set x-refresh-token-mode to 'header' to tell urBackend to read it from there.

Response Fields

Response Fields

string
The new short-lived JWT access token.
string
Human-readable duration until the new access token expires (e.g., "15m").

Code Examples

Success Response

Errors