---
title: "GET /oauth2/refresh_tokens/"
method: GET
path: "/oauth2/refresh_tokens/"
tags: ["oauth2"]
---

# GET /oauth2/refresh_tokens/

`GET /oauth2/refresh_tokens/`

RefreshToken Viewset

## Query parameters

- `ordering` string
- `page` integer
- `page_size` integer
- `provider` integer
- `search` string
- `user` integer

## Response `200`

- PaginatedTokenModelList
  - `pagination` Pagination, required
    - `next` number, required
    - `previous` number, required
    - `count` number, required
    - `current` number, required
    - `total_pages` number, required
    - `start_index` number, required
    - `end_index` number, required
  - `results` TokenModel[], required
    - `pk` integer, required
    - `provider` Provider, required — Provider Serializer
      - `pk` integer, required
      - `name` string, required
      - `authentication_flow` string, uuid, nullable — Flow used for authentication when the associated application is accessed by an un-authenticated user.
      - `authorization_flow` string, uuid, nullable — Flow used when authorizing this provider.
      - `invalidation_flow` string, uuid, nullable — Flow used ending the session from a provider.
      - `property_mappings` string[]
      - `component` string, required — Get object component so that we know how to edit the object
      - `assigned_application_slug` string, nullable, required — Internal application name, used in URLs.
      - `assigned_application_name` string, nullable, required — Application's display Name.
      - `assigned_backchannel_application_slug` string, nullable, required — Internal application name, used in URLs.
      - `assigned_backchannel_application_name` string, nullable, required — Application's display Name.
      - `verbose_name` string, required — Return object's verbose_name
      - `verbose_name_plural` string, required — Return object's plural verbose_name
      - `meta_model_name` string, required — Return internal model name
    - `user` User, required — User Serializer
      - `pk` integer, required
      - `username` string, required
      - `name` string, required — User's display name.
      - `is_active` boolean — Designates whether this user should be treated as active. Unselect this instead of deleting accounts.
      - `last_login` string, date-time, nullable
      - `date_joined` string, date-time, required
      - `is_superuser` boolean, required
      - `groups` string[]
      - `groups_obj` PartialGroup[], nullable, required
        - `pk` string, uuid, required
        - `num_pk` integer, required — Get a numerical, int32 ID for the group
        - `name` string, required
        - `is_superuser` boolean — Users added to this group will be superusers.
        - `attributes` object
      - `roles` string[]
      - `roles_obj` Role[], nullable, required
        - `pk` string, uuid, required
        - `name` string, required
      - `email` string, email
      - `avatar` string, required — User's avatar, either a http/https URL or a data URI
      - `attributes` object
      - `uid` string, required
      - `path` string
      - `type` 'internal' | 'external' | 'service_account' | 'internal_service_account'
      - `uuid` string, uuid, required
      - `password_change_date` string, date-time, required
      - `last_updated` string, date-time, required
    - `is_expired` boolean, required — Check if token is expired yet.
    - `expires` string, date-time, nullable
    - `scope` string[], required
    - `id_token` string, required — Get the token's id_token as JSON String
    - `revoked` boolean
  - `autocomplete` Autocomplete, required

## Other responses

- `400`
- `403`

---

[API](https://skmtc.dev/goauthentik/apis/authentik.md) · [All operations](https://skmtc.dev/goauthentik/apis/authentik/llms.txt) · [OpenAPI document](https://skmtc-service-production.skmtc.workers.dev/v1/apis/goauthentik/authentik/revisions/4e42e86021d7/schema)
