Concept Flow - Token refresh mechanism
Client sends login request
Server validates credentials
Server issues Access Token + Refresh Token
Client uses Access Token for API calls
Access Token expires?
No→Continue using API
Yes
Client sends Refresh Token to server
Server validates Refresh Token
Server issues new Access Token (and optionally new Refresh Token)
Client uses new Access Token
Repeat cycle
This flow shows how a client uses a refresh token to get a new access token when the old one expires, keeping the session alive without re-login.