---
title: "Refresh access token"
method: POST
path: "/auth/refresh"
tags: ["auth"]
---

# Refresh access token

`POST /auth/refresh`

Generate new access token using refresh token

## Headers

- `x-refresh-token` string, required
- `authorization` string, required

## Response `200`

Token refreshed successfully

- AuthResponse
  - `success` boolean, required
  - `msg` string, required
  - `data` object — Response payload (varies by endpoint)
    - `token` string — JWT access token
    - `user` User
      - `_id` string
      - `firstName` string
      - `lastName` string
      - `email` string, email
      - `role` string[]
      - `profileImage` string — URL or path to profile image
      - `isActive` boolean
      - `teamId` string
      - `createdAt` string, date-time
      - `updatedAt` string, date-time

## Other responses

- `401` — Authentication required or token invalid
- `500` — Internal server error

## Changes

- **2025-08-11** `db719f9e3d34` — 2 breaking, 3 warning, 9 info
  - removed the request body
  - the response's body type/format changed from `object`/`` to ``/`` for status `200`
  - removed the optional property `data` from the response with the `200` status
  - removed the optional property `msg` from the response with the `200` status
  - …10 more
- **2025-04-20** `b97ec6888b3c` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/bluewave-labs/apis/checkmate-api/changes/auth/refresh/post.md)

---

[API](https://skmtc.dev/bluewave-labs/apis/checkmate-api.md) · [All operations](https://skmtc.dev/bluewave-labs/apis/checkmate-api/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/bluewave-labs/checkmate-api/revisions/32614017d73a/schema)
