Theo's Typesafe CultTTC
Theo's Typesafe Cult3y ago
25 replies
chip

JWT and refresh tokens

I need some advice on how to handle refresh tokens 😦 Is it "good enough" if I generate two JWT tokens (accessToken, refreshToken), and let the resfrehToken just contain one claim, being the userID? And whenever I do a api call from the client and it returns a 401, I then call a /refresh api call, to get a new accessToken and retry the request - as long as the refreshToken is valid?
Was this page helpful?