Smart Capital Center API reference

refresh

POST
/api/v2/auth/refresh

Trades a refresh token for a new access token and a new refresh token. The old refresh token stops working immediately.

Auth: None

Use when: The access token has expired (after 900 seconds) and you still need bearer auth.

Don't use when: You are using an API key. API keys do not use refresh tokens.

Request body

Content type: application/json

Field Type Required Description
refresh_token string yes Opaque refresh token previously issued by /auth/login or /auth/refresh. Example: def50200b8f1aA-9V0p...rotated.

Notes for agents

  • Refresh tokens are single use. Save the new refresh_token before doing anything else.
  • Sending a refresh token that was already used is treated as a stolen token: every active session for that user is revoked and the call fails with 401. Never retry a refresh with a token you have already sent.

Example request

curl -X POST https://app.smartcapitalcenter.com/api/v2/auth/refresh \
  -H "Content-Type: application/json" \
  -d '{"refresh_token": "def50200..."}'

Response 200

Rotation successful — new token pair issued. The old refresh token is now invalid.

{
  "status": "success",
  "data": {
    "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...newsig",
    "refresh_token": "def50200ROTATED...",
    "expires_in": 900,
    "token_type": "Bearer"
  },
  "message": null,
  "code": null
}

Errors

Code Meaning
400 Validation error — missing refresh_token
401 Unknown / expired / already-revoked refresh token. If the token was already revoked, all active refresh tokens for the user are additionally revoked (reuse detection).

Next: Replace both stored tokens with the new pair.

# refresh `POST /api/v2/auth/refresh` Trades a refresh token for a new access token and a new refresh token. The old refresh token stops working immediately. **Auth:** None **Use when:** The access token has expired (after 900 seconds) and you still need bearer auth. **Don't use when:** You are using an API key. API keys do not use refresh tokens. ## Request body Content type: `application/json` | Field | Type | Required | Description | |---|---|---|---| | `refresh_token` | string | yes | Opaque refresh token previously issued by /auth/login or /auth/refresh. Example: `def50200b8f1aA-9V0p...rotated`. | ## Notes for agents - Refresh tokens are single use. Save the new `refresh_token` before doing anything else. - Sending a refresh token that was already used is treated as a stolen token: every active session for that user is revoked and the call fails with `401`. Never retry a refresh with a token you have already sent. ## Example request ```bash curl -X POST https://app.smartcapitalcenter.com/api/v2/auth/refresh \ -H "Content-Type: application/json" \ -d '{"refresh_token": "def50200..."}' ``` ## Response `200` Rotation successful — new token pair issued. The old refresh token is now invalid. ```json { "status": "success", "data": { "access_token": "eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9...newsig", "refresh_token": "def50200ROTATED...", "expires_in": 900, "token_type": "Bearer" }, "message": null, "code": null } ``` ## Errors | Code | Meaning | |---|---| | 400 | Validation error — missing refresh_token | | 401 | Unknown / expired / already-revoked refresh token. If the token was already revoked, all active refresh tokens for the user are additionally revoked (reuse detection). | **Next:** Replace both stored tokens with the new pair.