Refresh access token
/v1/auth/refreshRotates the session by reading the admin refresh token from its HttpOnly cookie (the body is ignored) and issuing a new access token plus a new refresh token, preserving the original Account and Application binding. Public but rate-limited to 60 per minute. The old refresh token is revoked on use; presenting an already-revoked token triggers reuse detection that revokes every refresh token for that user. Returns 401 when the cookie is missing, the token is unknown, expired, revoked, or the user or their Account membership is no longer active. New access token is Bearer with a 900s TTL.
Request body
application/json
refresh_tokenstring Optional Refresh token for backend (BFF) callers that hold the session server-side instead of in the httpOnly cookie. Omit for browser callers — the token is read from the cookie. Requires a matching secret `X-API-Key` to have the rotated token returned in the body.
Responses
application/json
data *AuthTokenResponseDto
application/json
error *ApiErrorBodyDto
Returned object
curl -X POST "https://auth.canopy-io.com/v1/auth/refresh" \ -H "Content-Type: application/json" \ -d '{ "refresh_token": "string" }'
{ "data": { "access_token": "string", "token_type": "string", "expires_in": 0, "user": { "id": "string", "email": "string", "first_name": "string", "last_name": "string" }, "default_environment_slug": "string" } }
Tell us how we can improve this guide.