Refresh Access Token
Exchange a valid refresh token for a new access token, without re-sending your API key. Call this whenever a request fails with 403 Invalid or expired access token.
Errors: 400 refresh token missing · 403 invalid company or invalid/expired refresh token.
Body (JSON)
Behaviour notes
- Returns only a new
accessToken; the refresh token is not rotated here. - No
Authorizationheader is needed for this call. - The KYB gate is checked live (no cache), so the same
403 KYB_REQUIRED/ACCOUNT_DEACTIVATEDbodies as Generate Access Token can come back. - A well-formed but superseded refresh token (one replaced by a later Generate Access Token call) returns
401 Unauthorized: Invalid API key; the message wrongly says “API key”. - A malformed or expired refresh token returns
403 Invalid or expired refresh token.
Request
This endpoint expects an object.
refreshToken
Response
OK
accessToken
Errors
400
Bad Request Error
401
Unauthorized Error
403
Forbidden Error
