post
https://api.wingspan.app/v3/platform/sessions/refresh
Exchanges a refresh token for a new session and ROTATES the refresh token. Public — the refresh token is itself the credential, so no Authorization bearer is required (the access token may already be expired; this is the renewal path). The 201 response carries a NEW token and a NEW refreshToken; the presented refresh token is single-use and is spent on success. A retry with the now-rotated token is treated as reuse and revokes the session — fall back to POST /sessions. Failures return 401 with a generic detail: "expired" vs "already-rotated" vs "forged" are deliberately indistinguishable.
Recent Requests
Log in to see full request history
| Time | Status | User Agent | |
|---|---|---|---|
Retrieving recent requests… | |||
Loading…