> ## Documentation Index
> Fetch the complete documentation index at: https://developer.jtl-software.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Refresh an on-behalf-of-user token

> Rotates an on-behalf-of-user token from its refresh token, returning a new access and refresh token with the same subject and claims. The app authenticates with its own service-account token in the Authorization header.



## OpenAPI

````yaml /openapi/account-service/token-exchange.json post /identity/act-as-user-token/refresh
openapi: 3.0.0
info:
  title: JTL Account Service - Token exchange
  version: v2
  description: >-
    Endpoints an app calls to mint and refresh delegated (act as a tenant
    install) and on-behalf-of-user (act as a user) tokens via RFC 8693 token
    exchange.
servers:
  - url: https://api.jtl-cloud.com/account
    description: Production
  - url: https://api.qa.jtl-cloud.com/account
    description: QA
  - url: https://api.dev.jtl-cloud.com/account
    description: Development
security: []
paths:
  /identity/act-as-user-token/refresh:
    post:
      tags:
        - Identity
      summary: Refresh an on-behalf-of-user token
      description: >-
        Rotates an on-behalf-of-user token from its refresh token, returning a
        new access and refresh token with the same subject and claims. The app
        authenticates with its own service-account token in the Authorization
        header.
      operationId: RefreshActAsUserToken
      requestBody:
        x-name: RefreshActAsUserTokenRequest
        description: ''
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/RefreshActAsUserTokenRequest'
        required: true
        x-position: 1
      responses:
        '200':
          description: The rotated access token, refresh token and lifetime.
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ActAsUserTokenResponse'
        '400':
          description: The refresh token is invalid, expired, revoked, or already rotated.
        '401':
          description: No bearer token was presented.
        '403':
          description: The caller carries no app id, or is no longer installed or opted in.
      security:
        - JWTBearerAuth: []
components:
  schemas:
    RefreshActAsUserTokenRequest:
      type: object
      description: >-
        Represents a request to rotate an on-behalf-of-user token from its
        refresh token. The app

        authenticates with its own service-account token (identified by its
        urn:jtl:app_id claim).
      additionalProperties: false
      required:
        - tenantId
        - refreshToken
      properties:
        tenantId:
          type: string
          description: >-
            Gets or sets the tenant the token was minted for; re-checked so
            uninstalling the app revokes rotation.
          minLength: 1
        refreshToken:
          type: string
          description: Gets or sets the on-behalf-of-user token's current refresh token.
          minLength: 1
    ActAsUserTokenResponse:
      type: object
      description: Represents the response for a minted on-behalf-of-user token.
      additionalProperties: false
      properties:
        accessToken:
          type: string
          description: Gets the user-subject access token minted for the calling app.
        refreshToken:
          type: string
          description: >-
            Gets the refresh token for rotating the access token for unattended,
            long-running access.
          nullable: true
        expiresIn:
          type: number
          description: Gets the access token lifetime in seconds.
          format: double
  securitySchemes:
    JWTBearerAuth:
      type: http
      description: Enter a JWT token to authorize the requests...
      scheme: Bearer
      bearerFormat: JWT

````