Refresh token
An OAuth 2.0 credential a client presents to the authorization server to get new access tokens without the user signing in again. It goes only to the authorization server, never to resource servers.
A refresh token is a credential defined in RFC 6749, the OAuth 2.0 framework (section 1.5), that a client uses to obtain a new access token when the current one expires or becomes invalid. Issuing one is optional, at the authorization server’s discretion. Unlike an access token, a refresh token is presented only to the authorization server and is never sent to a resource server. Short-lived access tokens limit what a stolen one is worth.
A refresh token commonly lives much longer, which makes it a valuable target. RFC 6749 section 10.4 requires it to be kept confidential in transit and storage and bound to its client. Where the client cannot be authenticated, the section offers refresh token rotation as an example: each refresh returns a new refresh token and invalidates the old one, so reuse of a stolen token by an attacker and the real client reveals the breach. Revoking a refresh token stops further renewal, although access tokens already issued may remain valid until they expire, particularly self-contained ones a resource server checks without asking the authorization server.
Exam relevance: a scenario is likely to ask why access tokens are kept short-lived, or how refresh token reuse can be detected. Candidates are expected to keep refresh and access tokens apart by audience and lifetime, and to recognise rotation as the reuse-detection control.