Refresh Token

POST /api/v1/auth/refresh

Rate limit: 30 requests per minute per IP (burst 15).

Issues a new access token and refresh token using the existing osprey_refresh cookie. No request body required โ€” the cookie is read automatically.

Refresh tokens rotate exactly once: consumption of the old token and creation of its successor occur in one transaction. Concurrent reuse is detected atomically, revokes the complete token family, and returns 401 rather than issuing a second successor.

Response: 200 OK (sets new cookies)

No JSON body returned.

Error responses: