Standard shape of the token/refresh API response (snake_case from backend).

interface TokenRefreshApiResponse {
    access_token: string;
    id_token: string;
    refresh_token?: string;
}

Properties

access_token: string
id_token: string
refresh_token?: string

Rotated refresh token. The backend spends the presented refresh token on every redemption and issues a new one; replaying a spent token is treated as reuse and terminates the whole login. Callers must persist this value. Optional only for backends that do not rotate.