General APIs with JWT

Swap the refresh cookie for a new one and a new access cookie (the web app calls it before the access cookie expires). A browser still holding the script-readable cookie from before gets its first HttpOnly pair here. The body never carries a token.

post/auth/refresh

Request

  • Base URL: https://lium.io/api
  • URL: https://lium.io/api/auth/refresh
  • Auth: none declared

Response

Successful Response

unknown required

Changes