POST
/api/v1/auth/refreshRefresh an access token
Exchanges the refresh token in the HttpOnly cookie for a new short-lived access token. Send the request with the refresh token cookie; the response includes the token's expiration time.
- IdempotentThe SDK sends
Idempotency-Key, so a retried request is only applied once.
200Returns a new short-lived access token and its expiration time.
accessTokenstringoptional
The new short-lived access token.
expiresAtstringoptional
When the access token expires.
defaultReturned when the request fails; includes an error code, a developer-facing message, and optional structured details.
codeintegeroptional
The status code, which should be an enum value of [google.rpc.Code][google.rpc.Code].
messagestringoptional
A developer-facing error message, which should be in English. Any user-facing error message should be localized and sent in the [google.rpc.Status.details][google.rpc.Status.details] field, or localized by the client.
detailsarray<object>optional
A list of messages that carry the error details. There is a common set of message types for APIs to use.
Error handling
Send a valid refresh token in the HttpOnly cookie. The request body defines no fields.
