Skip to main content

Command Palette

Search for a command to run...

Refresh-Token VS Access-Token

Updated
•2 min read•View as Markdown
K
i am a MERN developer and have interests in fitness,communicating/socalizing,etc

i am going to talk about both of the tokens in "JWT" Access Tokens are short lived tokens and Refresh Tokens are long lived tokens. we give permission to user to interact with our website via these tokens like after login it is assential for us to look for authuntification of the user. We can do that only with Access Tokens but the user needs to login again after the short time of access token are triggered example like Mongo Atlas still uses these technique to check authuntification of their users

So Google proposed an idea that we can have two tokens one in the user end-point and other in the database. Exactly that's how the Refresh Token idea entered in the dev community.

Now since i have explained you about this tokens let's see how they work. Refresh Token in the database it can be of 7 day to of 1 year or as long as you like. We compare Refresh Token with Access Token of the user to check if they're same or not on the besis of the result we will grant user the access

Access Tokens are keep on expiring in several time like 1 hours to 1 day. So it trigger an event in the database and get new access token if the new access token is equal to our stored refresh token we will grant user the access