1. auth
Autonomk
  • users
    • Get all users
      GET
    • Create User
      POST
    • Delete user
      DELETE
    • Get single user
      GET
    • Update User
      PUT
  • auth
    • Login
      POST
    • refresh token
      POST
    • Logout
      POST
  • chat
    • Chat
      POST
  • sessions
    • Get all logged in sessions
      GET
    • Delete logged in token
      DELETE
  • conversations
    • Get single conversation with chat messages
      GET
    • Get list of all conversations
      GET
    • Create Conversation History
      POST
    • Delete Conversation History
      DELETE
    • Update the conversation properties
      PATCH
    • insert chat into conversation
      PATCH
  • Untitled Endpoint
    POST
  1. auth

refresh token

Developing
Development
http://localhost:8080/api/v0
Development
http://localhost:8080/api/v0
POST
http://localhost:8080/api/v0
/auth/refresh-token

Purpose:#

Refresh the access token and refresh token

Use:#

When the app is loaded or refreshed a call is made to refresh the access token and refresh token.

Notes:#

1.
The access token is sent as a field in the response body, and stored in memory. If this is a client side token (e.g JWT) then make this short-lived (10m-15m).
2.
The refresh token should be sent in the cookie of the response for this call, and will automatically be included in the cookies of the request for all other calls. This helps with silent authentication of the user.
3.
This call allows for the refresh token to be null, this will be particularly useful when session authentication (server side) is required. No refresh token is sent in any calls. On refreshing the app the user will be logged out and will have to re-authenticate via the login page.
4.
The fetch method credentials by default are set to same-origin, however these can be changed in the /public/scripts/env.js file you can set to either omit or include. e.g.
FETCH_CREDENTIALS : "include"
include will allow cross-origin calls and should only be used in development or testing. same-origin will not allow cross-origin data to be sent, and hence is the default.
https://developer.mozilla.org/en-US/docs/Web/API/Fetch_API/Using_Fetch
If the value for credential is not recogonised, then same-origin will be used.

Request

Authorization
Provide your bearer token in the
Authorization
header when making requests to protected resources.
Example:
Authorization: Bearer ********************
Body Params application/json

Examples

Responses

🟢200Success
application/json
Bodyapplication/json

🟠400Bad Request
🟠403Forbidden
🟠401Unathorized
🟠422Unprocessable Entity
🟠404Not found
Request Request Example
Shell
JavaScript
Java
Swift
curl --location 'http://localhost:8080/api/v0/auth/refresh-token' \
--header 'Authorization: Bearer <token>' \
--header 'Content-Type: application/json' \
--data '{
    "id": "68503638b86e9eb6df2875e6",
    "refresh_token": "npY79AtflQqF7jMc/vSBiBZ02MoOKLNGb5xB4xavBPU="
}'
Response Response Example
200 - Example 1
{
    "token": "01988578-a111-7d4a-a675-0980f37a0b55",
    "username" : "john.doe"
}
Modified at 2025-08-09 14:45:05
Previous
Login
Next
Logout
Built with