Refresh Token
POST /api/v1/auth/refresh
Rate limit: 30 requests per minute per IP (burst 15).
Issues a new access token and refresh token using the existing osprey_refresh cookie. No request body required โ the cookie is read automatically.
Refresh tokens rotate exactly once: consumption of the old token and creation of its successor occur in one transaction. Concurrent reuse is detected atomically, revokes the complete token family, and returns 401 rather than issuing a second successor.
Response: 200 OK (sets new cookies)
No JSON body returned.
Error responses:
401 Unauthorized โ No refresh cookie, invalid token, expired token, or replay detected (used token resubmitted).