Skip to main content

POST /v1/auth/refresh

POST 

/v1/auth/refresh

Exchange the rotating uniqos_refresh cookie for a new access token and a rotated refresh cookie. Replaying an already-rotated token within the rotation grace window re-rotates (rapid-reload race); after the window it revokes the entire session family and returns 401.

Responses

Default Response

Response Headers
    X-Request-Id

    ULID stamped on every response and propagated through error envelopes. Use it when filing support tickets — it identifies the exact request in the structured logs (requestId field).

    X-RateLimit-Limit

    Requests-per-second ceiling for the current bucket (per-organization for authenticated calls, per-IP for public ones).

    X-RateLimit-Remaining

    Tokens left in the bucket after this request.

    X-RateLimit-Reset

    ISO-8601 timestamp when the bucket will be fully refilled.