Skip to main content
POST
Token Refresh

Overview

The token refresh endpoint allows you to obtain a new JWT access token using a valid refresh token. This is essential for maintaining long-lived sessions without requiring users to re-authenticate.

Endpoint

Request Body

string
required
The JWT refresh token received from sign-in or sign-up endpoints.

Response

string
A new JWT access token that can be used to authenticate API requests.
string
In some configurations, a new refresh token may also be returned. Check your JWT settings to determine if refresh token rotation is enabled.

Example Request

cURL
Python
JavaScript

Example Response

200 OK

Error Responses

401 Unauthorized - Invalid Token
401 Unauthorized - Token Blacklisted
400 Bad Request - Missing Refresh Token

Implementation Details

This endpoint is provided by Django REST Framework SimpleJWT library. The configuration is set up in backend/urls.py:16:

Token Lifecycle

1. Initial Authentication

When a user signs in or signs up, they receive both tokens:
  • Access Token: Short-lived (typically 5-60 minutes)
  • Refresh Token: Long-lived (typically days or weeks)

2. Making API Requests

Use the access token in the Authorization header:

3. Access Token Expiration

When an access token expires, API requests will return a 401 Unauthorized error.

4. Token Refresh

Instead of asking the user to log in again:
  1. Call /api/token/refresh/ with the refresh token
  2. Receive a new access token
  3. Continue making authenticated requests

5. Refresh Token Expiration

When the refresh token expires, the user must sign in again.

Automatic Token Refresh Pattern

Here’s a recommended pattern for handling token refresh automatically:
JavaScript - Axios Interceptor
Python - Request Wrapper

Security Best Practices

  1. Secure Storage: Store tokens securely
    • In browsers: Use httpOnly cookies or secure storage mechanisms
    • In mobile apps: Use secure storage APIs (Keychain, KeyStore)
    • Never store tokens in localStorage in production for sensitive applications
  2. Token Expiration: Configure appropriate token lifetimes in your Django settings
  3. HTTPS Only: Always use HTTPS in production to prevent token interception
  4. Token Revocation: Consider implementing token blacklisting for logout functionality

Notes

  • This endpoint is provided by rest_framework_simplejwt.views.TokenRefreshView
  • The endpoint does not require authentication (the refresh token itself serves as authentication)
  • Refresh tokens are typically longer-lived than access tokens
  • If a refresh token is expired or invalid, the user must sign in again
  • The response may include a new refresh token if token rotation is enabled in settings