---
title: "Reissue a direct token without changing which resource it is bound to."
method: POST
path: "/auth/boot/refresh"
tags: ["Auth"]
---

# Reissue a direct token without changing which resource it is bound to.

`POST /auth/boot/refresh`

Extends a boot session past the 4 hour token expiry while keeping the same
`allowed_resource_id`, so a conversation in progress is not interrupted.

Unlike `POST /auth/boot` this endpoint is authenticated: present the current
direct token as `Bearer <token>`. The resource assignment is copied from that
token and never read from the request body, so a caller cannot name a
resource it does not already hold.

Refreshing does not extend a session indefinitely. Each token carries an
absolute ceiling fixed at the original boot, and the reissued token inherits
it unchanged. Revoking the direct link (regenerating its hash), deleting the
direct record, or deactivating the customer all take effect on the next
refresh.

## Response `200`

Token reissued. `allowed_resource_id` and `scope_version` are unchanged;
only `expire` moves. `resource_data` is always omitted here (the client
already holds it from the original boot), so the response is the boot
response minus that field.

- AuthBootResponse — Result of a successful boot request. Contains a resource-scoped JWT and metadata about the scoped resource.
  - `token` string — JWT token string for API authentication. Pass as `Bearer <token>` in the Authorization header.
  - `type` 'direct' — Token type. Always "direct" for boot tokens.
  - `resource_type` string — The type of resource this token is scoped to (e.g., "ai").
  - `resource_id` string, uuid — The UUID of the resource this token is scoped to. Returned from the resource creation endpoint (e.g., `POST /ais`).
  - `customer_id` string, uuid — The UUID of the customer that owns the resource. Returned from the `POST /auth/signup` response.
  - `expire` string, date-time — Token expiry timestamp in ISO 8601 format.
  - `allowed_resource_id` string, uuid — The single resource this token may act on, assigned at boot before the resource exists. The resource created with this token takes this id, so two visitors of the same public link cannot reach each other's conversation. Clients do not need to send it anywhere; the server takes the target from the token.
  - `scope_version` integer — Version of the token's scope contract. Bumping it invalidates every outstanding token in one step; clients treat the resulting 401 as a signal to boot again.
  - `resource_data` object, nullable — Resource-type-scoped envelope for additional, publicly-safe data about the boot-scoped resource. Each entry is a self-documenting named key; currently only "public_display_config" is populated (for resource_type "webchat_widget", carrying the widget's WebchatManagerWidgetThemeConfig shape). The envelope key itself, and any entry inside it, is OMITTED (not present) when there is nothing to report -- never present as an empty object.
    - `public_display_config` WebchatManagerWidgetThemeConfig — Cosmetic, customer-editable widget appearance settings. All fields are optional; omitted fields fall back to the platform default (blue bubble, no logo, bottom-right, light mode). An explicit color field always wins over the theme_mode-resolved default.
      - `primary_color` string — Hex color code for the widget's primary color.
      - `secondary_color` string — Hex color code for the widget's accent/text-contrast color.
      - `header_background_color` string — Hex color code for the widget header bar's background. Falls back to primary_color (light mode) or a dark surface color (dark mode) when unset.
      - `header_text_color` string — Hex color code for the widget header bar's text.
      - `logo_url` string, uri — HTTPS URL of the logo image displayed in the widget header.
      - `position` 'bottom_right' | 'bottom_left' — Where the floating bubble/panel renders on the customer's page.
      - `theme_mode` 'light' | 'dark' | 'auto' — Controls light/dark/auto rendering of the widget panel.
      - `header_title` string — Widget header text. Defaults to "Chat with us" when unset.
      - `header_subtitle` string — Widget header subtext, shown below header_title. No subtitle row rendered when unset.
      - `connecting_indicator_enabled` boolean, nullable — Whether to show a system message in the panel while the visitor's session is being created. Unset/null falls back to enabled (true); an existing widget's default is preserved by omitting this key rather than sending false.
      - `connecting_indicator_text` string — Text shown while the visitor's session is being created. Defaults to "Connecting…" when unset.
      - `typing_indicator_enabled` boolean, nullable — Whether to show the three-dot "waiting for response" animation after the visitor sends a message. Unset/null falls back to enabled (true). No text-label variant is supported.
      - `border_radius` 'sharp' | 'rounded' | 'pill' — Corner rounding applied to the bubble, panel, message bubbles, input field, and send button as a coordinated set. Defaults to rounded when unset.
      - `font_size` 'compact' | 'default' | 'large' — Base font-size scale applied to the widget's header text and message text. Defaults to default when unset.

## Other responses

- `401` — The token can no longer be refreshed. Boot again. Possible causes: - The token predates resource binding and carries no assignment. - The boot session's absolute lifetime has elapsed. - The direct link was deleted or its hash was regenerated. - The owning customer is no longer active.
- `403` — The presented token is not a direct token.
- `500` — The server could not issue a token. Retrying the refresh may succeed; booting again will not help.

## Changes

- **2026-09-08** `7b9e8b2dd029` — 1 info
  - endpoint added

[Change history](https://skmtc.dev/voipbin/apis/voipbin-api/changes/auth/boot/refresh/post.md)

---

[API](https://skmtc.dev/voipbin/apis/voipbin-api.md) · [All operations](https://skmtc.dev/voipbin/apis/voipbin-api/llms.txt) · [OpenAPI document](https://skmtc.dev/voipbin/apis/voipbin-api/revisions/6a2b13260ccc?raw)
