freecoding.school100% FREE · NO SIGNUP
Endpoint BayISSUE #41 of 45

refresh tokens · keeping sessions alive

RestaVSThe 401 Bandit
Resta saysRefresh tokens get new access tokens without re-login — keeping sessions alive safely.

Access tokens are short-lived (minutes) to limit damage if leaked. A longer-lived refresh token (stored securely, server-side or in an HttpOnly cookie) is exchanged for a fresh access token when the old one expires — silently, no re-login. Refresh tokens can be revoked, giving you both convenience and a kill switch.

Power-ups you unlock

The 401 Bandit attacks — common mistakes

Boss battleExplain why short access + long refresh beats one long-lived token.

Example code

<!doctype html><html><head><meta charset="utf-8"></head>
<body style="background:#06040d;color:#e6e0ff;font-family:monospace;padding:20px"><pre>access token  → 15 min (sent on every call)
refresh token → days (HttpOnly, revocable)
expiry → refresh → new access, no re-login</pre></body></html>
▶ Open the interactive comic issue
‹ Jwt · Header · Payload · SignatureSession Cookies · Server-Managed Sessions ›