A long-lived OAuth 2.0 credential that the client uses to obtain new short-lived access tokens without re-prompting the user for credentials — separates session lifetime from token-leak blast radius.
Refresh Tokens solve the access-token tradeoff: short-lived tokens (minutes to hours) limit damage from leaks but require frequent re-auth; long-lived tokens (months) reduce friction but greatly amplify leak damage. The Refresh Token pattern issues both: a short access token (15-60 min) for actual API calls and a long refresh token (days to months) stored securely and used only to mint new access tokens. Refresh tokens can also be revoked centrally if leaked.
User logs in once → app receives 15-min access token + 30-day refresh token → access token expires → app exchanges refresh token for new access token, no re-login.
Refresh Tokens enable the modern 'log in once, stay logged in for weeks' user experience without sacrificing security.
Need help implementing this in your business?
Get Started