Skip to main content
refresh_token here means the value returned alongside token from signup/login - not the access token itself. Sending the access token as refresh_token is a real mistake to guard against: it fails silently (the exchange just gets rejected) rather than throwing something obviously wrong.

The unified token() exchange

login() and refreshToken() are both thin wrappers around token(), which accepts either grant type directly - useful if you’re building your own auth flow on top: