Refresh Token
  • is a credential used to obtain access tokens. Refresh tokens are issued to the client by the authorization server and are used to obtain a new access token when the current one becomes invalid or expires, or to obtain additional access tokens with identical or narrower scope
  • unlike access tokens, refresh tokens are intended for use only with authorization servers and are never sent to resource servers
  • as for access tokens a refresh token is represented as a string that is usually opaque to the client

Refresh Token - Example

refresh_token=9yNOxJtZa5