> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.shimi.cash/api-reference/shimi-api/authentication/refresh-access-token/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.shimi.cash/_mcp/server. # Refresh Access Token POST https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/ Content-Type: application/json Exchange a valid refresh token for a new access token, without re-sending your API key. Call this whenever a request fails with `403 Invalid or expired access token`. **Errors:** `400` refresh token missing ยท `403` invalid company or invalid/expired refresh token. **Body (JSON)** | Field | Type | Required | Notes | |---|---|---|---| | `refreshToken` | string (JWT) | yes | The most recent `refreshToken` from Generate Access Token. | **Behaviour notes** - Returns only a new `accessToken`; the refresh token is not rotated here. - No `Authorization` header is needed for this call. - The KYB gate is checked live (no cache), so the same `403 KYB_REQUIRED` / `ACCOUNT_DEACTIVATED` bodies as Generate Access Token can come back. - A well-formed but superseded refresh token (one replaced by a later Generate Access Token call) returns `401 Unauthorized: Invalid API key`; the message wrongly says "API key". - A malformed or expired refresh token returns `403 Invalid or expired refresh token`. Reference: https://docs.shimi.cash/api-reference/shimi-api/authentication/refresh-access-token ## Request ### Body (application/json) This endpoint expects an object. - `refreshToken` (string, optional) ## Response ### 200 OK - `accessToken` (string, optional) ## Errors ### 400 Bad Request Error Bad Request - `message` (string, optional) ### 401 Unauthorized Error Unauthorized - `message` (string, optional) ### 403 Forbidden Error Invalid or expired refresh token / Invalid company - `message` (string, optional) ## Examples ### 200 Success **Response** ```json { "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyZWZlcmVuY2UiOiJjbWcxYTdyMmswMDAwYWIxMmNkMzRlZjU2IiwiaWF0IjoxNzkxMTE1MjAwLCJleHAiOjE3OTExMTg4MDB9.4fT0nR8qWz3m1Xk7pLcV2bH9yJdE6sGuA5oYtKiN0Qw" } ``` **SDK Code** ```python 200 Success import requests url = "https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/" response = requests.post(url) print(response.json()) ``` ```javascript 200 Success const url = 'https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/'; const options = {method: 'POST'}; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go 200 Success package main import ( "fmt" "net/http" "io" ) func main() { url := "https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/" req, _ := http.NewRequest("POST", url, nil) res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby 200 Success require 'uri' require 'net/http' url = URI("https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) response = http.request(request) puts response.read_body ``` ```java 200 Success import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/") .asString(); ``` ```php 200 Success request('POST', 'https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/'); echo $response->getBody(); ``` ```csharp 200 Success using RestSharp; var client = new RestClient("https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/"); var request = new RestRequest(Method.POST); IRestResponse response = client.Execute(request); ``` ```swift 200 Success import Foundation let request = NSMutableURLRequest(url: NSURL(string: "https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ``` ### Authentication_refreshAccessToken_example **Request** ```json { "refreshToken": "{{refresh_token}}" } ``` **Response** ```json { "accessToken": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJyZWZlcmVuY2UiOiJjbWcxYTdyMmswMDAwYWIxMmNkMzRlZjU2IiwiaWF0IjoxNzkxMTE1MjAwLCJleHAiOjE3OTExMTg4MDB9.4fT0nR8qWz3m1Xk7pLcV2bH9yJdE6sGuA5oYtKiN0Qw" } ``` **SDK Code** ```python Authentication_refreshAccessToken_example import requests url = "https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/" payload = { "refreshToken": "{{refresh_token}}" } headers = {"Content-Type": "application/json"} response = requests.post(url, json=payload, headers=headers) print(response.json()) ``` ```javascript Authentication_refreshAccessToken_example const url = 'https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/'; const options = { method: 'POST', headers: {'Content-Type': 'application/json'}, body: '{"refreshToken":"{{refresh_token}}"}' }; try { const response = await fetch(url, options); const data = await response.json(); console.log(data); } catch (error) { console.error(error); } ``` ```go Authentication_refreshAccessToken_example package main import ( "fmt" "strings" "net/http" "io" ) func main() { url := "https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/" payload := strings.NewReader("{\n \"refreshToken\": \"{{refresh_token}}\"\n}") req, _ := http.NewRequest("POST", url, payload) req.Header.Add("Content-Type", "application/json") res, _ := http.DefaultClient.Do(req) defer res.Body.Close() body, _ := io.ReadAll(res.Body) fmt.Println(res) fmt.Println(string(body)) } ``` ```ruby Authentication_refreshAccessToken_example require 'uri' require 'net/http' url = URI("https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/") http = Net::HTTP.new(url.host, url.port) http.use_ssl = true request = Net::HTTP::Post.new(url) request["Content-Type"] = 'application/json' request.body = "{\n \"refreshToken\": \"{{refresh_token}}\"\n}" response = http.request(request) puts response.read_body ``` ```java Authentication_refreshAccessToken_example import com.mashape.unirest.http.HttpResponse; import com.mashape.unirest.http.Unirest; HttpResponse response = Unirest.post("https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/") .header("Content-Type", "application/json") .body("{\n \"refreshToken\": \"{{refresh_token}}\"\n}") .asString(); ``` ```php Authentication_refreshAccessToken_example request('POST', 'https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/', [ 'body' => '{ "refreshToken": "{{refresh_token}}" }', 'headers' => [ 'Content-Type' => 'application/json', ], ]); echo $response->getBody(); ``` ```csharp Authentication_refreshAccessToken_example using RestSharp; var client = new RestClient("https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/"); var request = new RestRequest(Method.POST); request.AddHeader("Content-Type", "application/json"); request.AddParameter("application/json", "{\n \"refreshToken\": \"{{refresh_token}}\"\n}", ParameterType.RequestBody); IRestResponse response = client.Execute(request); ``` ```swift Authentication_refreshAccessToken_example import Foundation let headers = ["Content-Type": "application/json"] let parameters = ["refreshToken": "{{refresh_token}}"] as [String : Any] let postData = JSONSerialization.data(withJSONObject: parameters, options: []) let request = NSMutableURLRequest(url: NSURL(string: "https://shimi-waas-api-9493532b9281.herokuapp.com/api/v1/auth/refresh-access-token/")! as URL, cachePolicy: .useProtocolCachePolicy, timeoutInterval: 10.0) request.httpMethod = "POST" request.allHTTPHeaderFields = headers request.httpBody = postData as Data let session = URLSession.shared let dataTask = session.dataTask(with: request as URLRequest, completionHandler: { (data, response, error) -> Void in if (error != nil) { print(error as Any) } else { let httpResponse = response as? HTTPURLResponse print(httpResponse) } }) dataTask.resume() ```