# refresh-token

Source: https://startwithidentity.com/glossary/refresh-token/
Last updated: 2026-08-29
License: content by Start with Identity. Cite the source URL.

---

A longer-lived credential used to obtain new access tokens without re-authenticating the user. Refresh tokens should be one-time-use (rotated on each exchange) and bound to the client. Storing them carelessly is one of the most common identity security failures.

Refresh tokens are the highest-value credential in most OAuth deployments because they mint new access tokens without any user interaction, and stolen ones are what turn a browser compromise into months of access. Rotate on every use and detect reuse of an already-spent token, which is the signal that a copy is circulating. Bind them to the client, and keep them out of local storage in browsers.

See also: [access token](https://startwithidentity.com/glossary/access-token/), [token theft](https://startwithidentity.com/glossary/token-theft/), [DPoP](https://startwithidentity.com/glossary/dpop/), [OAuth 2.1](https://startwithidentity.com/standards/oauth-2-1/)
