Exchanges a valid refresh token for a new access token and a new refresh token.
This endpoint implements refresh token rotation for enhanced security:
Usage Flow:
access_token and refresh_tokenaccess_token expires (typically 15 minutes), client calls this endpoint with refresh_tokenaccess_token and a new refresh_tokenrefresh_token and uses the new one for future refreshesSecurity Notes:
Documentation Index
Fetch the complete documentation index at: https://docs.crypto.westminister.tech/llms.txt
Use this file to discover all available pages before exploring further.
Request payload for refreshing an access token.
The refresh token previously issued by a login endpoint.
"a1b2c3d4-e5f6-7890-abcd-ef1234567890"
Token refreshed successfully
Authentication response returned by login endpoints.
Short-lived PASETO bearer token used for authenticated API calls.
"v4.local.eyJzdWIiOiJ1c2VyLWlkIiwicm9sZSI6InVzZXIifQ..."
Long-lived refresh token used to obtain new access tokens. Store securely and never expose in URLs or logs.
"a1b2c3d4-e5f6-7890-abcd-ef1234567890"
Token type, typically 'bearer'.
"bearer"
Access token lifetime in seconds.
900