Token Refresh
Authentication
Token Refresh
Obtain a new access token using a refresh token
POST
Token Refresh
Overview
The token refresh endpoint allows you to obtain a new JWT access token using a valid refresh token. This is essential for maintaining long-lived sessions without requiring users to re-authenticate.Endpoint
Request Body
string
required
The JWT refresh token received from sign-in or sign-up endpoints.
Response
string
A new JWT access token that can be used to authenticate API requests.
string
In some configurations, a new refresh token may also be returned. Check your JWT settings to determine if refresh token rotation is enabled.
Example Request
cURL
Python
JavaScript
Example Response
200 OK
Error Responses
401 Unauthorized - Invalid Token
401 Unauthorized - Token Blacklisted
400 Bad Request - Missing Refresh Token
Implementation Details
This endpoint is provided by Django REST Framework SimpleJWT library. The configuration is set up inbackend/urls.py:16:
Token Lifecycle
1. Initial Authentication
When a user signs in or signs up, they receive both tokens:- Access Token: Short-lived (typically 5-60 minutes)
- Refresh Token: Long-lived (typically days or weeks)
2. Making API Requests
Use the access token in the Authorization header:3. Access Token Expiration
When an access token expires, API requests will return a 401 Unauthorized error.4. Token Refresh
Instead of asking the user to log in again:- Call
/api/token/refresh/with the refresh token - Receive a new access token
- Continue making authenticated requests
5. Refresh Token Expiration
When the refresh token expires, the user must sign in again.Automatic Token Refresh Pattern
Here’s a recommended pattern for handling token refresh automatically:JavaScript - Axios Interceptor
Python - Request Wrapper
Security Best Practices
-
Secure Storage: Store tokens securely
- In browsers: Use httpOnly cookies or secure storage mechanisms
- In mobile apps: Use secure storage APIs (Keychain, KeyStore)
- Never store tokens in localStorage in production for sensitive applications
-
Token Expiration: Configure appropriate token lifetimes in your Django settings
- HTTPS Only: Always use HTTPS in production to prevent token interception
- Token Revocation: Consider implementing token blacklisting for logout functionality
Notes
- This endpoint is provided by
rest_framework_simplejwt.views.TokenRefreshView - The endpoint does not require authentication (the refresh token itself serves as authentication)
- Refresh tokens are typically longer-lived than access tokens
- If a refresh token is expired or invalid, the user must sign in again
- The response may include a new refresh token if token rotation is enabled in settings
