Skip to main content
POST
Refresh an on-behalf-of-user token

Body

application/json

Represents a request to rotate an on-behalf-of-user token from its refresh token. The app authenticates with its own service-account token (identified by its urn:jtl:app_id claim).

tenantId
string
required

Gets or sets the tenant the token was minted for; re-checked so uninstalling the app revokes rotation.

Minimum string length: 1
refreshToken
string
required

Gets or sets the on-behalf-of-user token's current refresh token.

Minimum string length: 1

Response

The rotated access token, refresh token and lifetime.

Represents the response for a minted on-behalf-of-user token.

accessToken
string

Gets the user-subject access token minted for the calling app.

refreshToken
string | null

Gets the refresh token for rotating the access token for unattended, long-running access.

expiresIn
number<double>

Gets the access token lifetime in seconds.