Skip to content

Refresh access token ​

Get a new access token using a refresh token, without re-sending your password.

POST/api/v2/auth/tokenNo auth

Refresh tokens are single-use

Every refresh returns a new refresh token and invalidates the old one. Always store the refresh token from the latest response.

Request body ​

FieldTypeRequiredDescription
grant_typestringrequiredMust be refresh_token
refresh_tokenstringrequiredYour most recent refresh token
json
{
  "grant_type": "refresh_token",
  "refresh_token": "v2.local.Ao46TCfIN_TYe524sreTrOmMjaCfXwKtzL76VGF007AU…"
}

Response ​

200 OK

Same shape as Get access token:

json
{
  "code": "OK",
  "data": {
    "session_id": "c2b7e0a1-5f3d-4c8e-9a61-2d7f4e8b1c90",
    "access_token": "v2.local.NTvaU6-xmM2yIkLMQMm8VB_YH3R114MKd…",
    "access_token_expires_at": "2026-06-20T10:29:57.873669Z",
    "refresh_token": "v2.local.XjpubecZzsZAAeAGfhObnolLuqeo6ku1i…",
    "refresh_token_expires_at": "2026-06-20T18:14:57.873939Z"
  }
}

Errors ​

HTTPCodeWhen
404credential.invalid_tokenRefresh token not recognised — log in with your password
403credential.token_blockedRefresh token already used or revoked — log in again

Need help? Contact your DMC Pay account manager.