Refresh a session (rotates the refresh token)

Exchanges a refresh token for a new session and ROTATES the refresh token. Public — the refresh token is itself the credential, so no Authorization bearer is required (the access token may already be expired; this is the renewal path). The 201 response carries a NEW token and a NEW refreshToken; the presented refresh token is single-use and is spent on success. A retry with the now-rotated token is treated as reuse and revokes the session — fall back to POST /sessions. Failures return 401 with a generic detail: "expired" vs "already-rotated" vs "forged" are deliberately indistinguishable.

Recent Requests
Log in to see full request history
TimeStatusUser Agent
Retrieving recent requests…
LoadingLoading…
Body Params
string
required
length between 1 and 4096

The opaque refresh token returned by a prior create or refresh response. Single-use — spent (rotated) on success.

Headers
string
enum
Defaults to application/json

Generated from available response content types

Allowed:
Responses

Language
LoadingLoading…
Response
Click Try It! to start a request and see the response here! Or choose an example:
application/json
application/problem+json