Refresh a user session
Exchanges a refresh token (sent in the `Refresh-Token` header) for a fresh access/refresh token pair. Use when the access token is about to expire or has expired.
/auth/refreshExchanges a refresh token (sent in the Refresh-Token header) for
a fresh access/refresh token pair. Use when the access token is
about to expire or has expired.
Header Parameters
The refresh token to exchange.
Response Body
application/json
application/json
application/json
application/json
curl -X POST "https://example.com/auth/refresh" \ -H "Refresh-Token: string"{
"code": 200,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"pagination": {
"page": 1,
"limit": 1,
"total": 0,
"has_next": true,
"has_prev": true,
"next_page": 0,
"prev_page": 0
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "string",
"data": {
"access_token": "string",
"refresh_token": "string",
"access_expires_at": "2019-08-24T14:15:22Z",
"refresh_expires_at": "2019-08-24T14:15:22Z",
"domain": "string"
}
}{
"code": 0,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "IdentityX"
}{
"code": 0,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "IdentityX"
}{
"code": 0,
"message": "string",
"error": {
"code": "BAD_REQUEST",
"message": "string",
"fields": [
{
"field": "string",
"message": "string"
}
],
"meta": {},
"debug": {
"raw_error": "string",
"stack_trace": "string"
}
},
"timestamp": "2019-08-24T14:15:22Z",
"module": "IdentityX"
}Log out a user POST
Logs out the current session, blacklisting the presented access and refresh tokens. Requires a valid bearer token; the tokens to blacklist are read from the request headers.
Start a social login GET
Starts the social login process for the given provider (`google` or `github`) and returns the redirect URL the client should send the user to. After the user authorizes, the provider redirects back to `/auth/{provider}/callback?code=...`.