Resta saysRefresh tokens get new access tokens without re-login — keeping sessions alive safely.
Access tokens are short-lived (minutes) to limit damage if leaked. A longer-lived refresh token (stored securely, server-side or in an HttpOnly cookie) is exchanged for a fresh access token when the old one expires — silently, no re-login. Refresh tokens can be revoked, giving you both convenience and a kill switch.
Power-ups you unlock
Short access token + long refresh token
Refresh swaps in a new access token silently
Store refresh tokens securely (HttpOnly)
Refresh tokens are revocable (the kill switch)
The 401 Bandit attacks — common mistakes
Long-lived access tokens with no refresh
Refresh tokens in localStorage (XSS-readable)
No rotation/revocation on refresh
Boss battleExplain why short access + long refresh beats one long-lived token.
Example code
<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>access token → 15 min (sent on every call)
refresh token → days (HttpOnly, revocable)
expiry → refresh → new access, no re-login</pre></body></html>