Trades a refresh token for a new access token and a new refresh token. The old refresh token stops working immediately.
Auth: None
Use when: The access token has expired (after 900 seconds) and you still need bearer auth.
Don't use when: You are using an API key. API keys do not use refresh tokens.
Content type: application/json
| Field | Type | Required | Description |
|---|---|---|---|
refresh_token |
string | yes | Opaque refresh token previously issued by /auth/login or /auth/refresh. Example: def50200b8f1aA-9V0p...rotated. |
refresh_token before doing anything else.401. Never retry a refresh with a token you have already sent.curl -X POST https://app.smartcapitalcenter.com/api/v2/auth/refresh \
-H "Content-Type: application/json" \
-d '{"refresh_token": "def50200..."}'
200Rotation successful — new token pair issued. The old refresh token is now invalid.
{
"status": "success",
"data": {
"access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...newsig",
"refresh_token": "def50200ROTATED...",
"expires_in": 900,
"token_type": "Bearer"
},
"message": null,
"code": null
}
| Code | Meaning |
|---|---|
| 400 | Validation error — missing refresh_token |
| 401 | Unknown / expired / already-revoked refresh token. If the token was already revoked, all active refresh tokens for the user are additionally revoked (reuse detection). |
Next: Replace both stored tokens with the new pair.