Skip to navigation

Refresh Access Token

View as Markdown

Exchange a valid refresh token for a new access token, without re-sending your API key. Call this whenever a request fails with 403 Invalid or expired access token.

Errors: 400 refresh token missing · 403 invalid company or invalid/expired refresh token.

Body (JSON)

FieldTypeRequiredNotes
refreshTokenstring (JWT)yesThe most recent refreshToken from Generate Access Token.

Behaviour notes

  • Returns only a new accessToken; the refresh token is not rotated here.
  • No Authorization header is needed for this call.
  • The KYB gate is checked live (no cache), so the same 403 KYB_REQUIRED / ACCOUNT_DEACTIVATED bodies as Generate Access Token can come back.
  • A well-formed but superseded refresh token (one replaced by a later Generate Access Token call) returns 401 Unauthorized: Invalid API key; the message wrongly says “API key”.
  • A malformed or expired refresh token returns 403 Invalid or expired refresh token.

Request

This endpoint expects an object.
refreshTokenstringOptional

Response

OK
accessTokenstringOptional

Errors

400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error