Authentication · FAQ
What happens when my access token expires?
When your access token expires, exchange the refresh token at the token endpoint with grant_type=refresh_token, your client_id, and resource; the expires_in value in the token response is the authoritative lifetime.
A 401 with error="invalid_token" on a token that used to work means it has expired, been revoked, or is bound to another resource. Refresh it, and if the refresh fails, send the person through authorization again. Keep the client and its client_id; don't register again. The documentation publishes no token lifetime beyond expires_in. For the REST API, GET /refresh-token renews the JWT, and a 401 from that endpoint means you need to log in again.
See: Authentication and casafari.com/auth.md.