Skip to main content

Command Palette

Search for a command to run...

AccessToken and RefreshToken

Published
•1 min read•View as Markdown
C

Learning and explore in tech field.

1. Access Token

Access token (generated in authorization server) allows temporary to restricted resources like API.

Access tokens are short-lived. These tokens are valid for only a few hours or something like that. Any user with an access token is automatically authenticated.

2 . Refresh Token

Refresh tokens allow users to log in and stay connected without providing their password for long periods.

Refresh tokens are long-lived. Refresh tokens can last from a few days to a few months. It improves the user experience. we can generate access tokens via refresh tokens.

const user = await User.findById(userId);
     const refreshToken = user.generateRefreshToken();
      const accessToken = user.generateAccessToken();
      user.refreshToken = refreshToken;
      user.save({validateBeforeSave: false});
      return {accessToken, refreshToken};

How to get these tokens: from jsonwebtoken

Install in Node js

npm i jsonwebtoken

Image from stack overflow

If you want to learn how to implement all these things

"Chai aur code" Youtube channel

Click Here [Video]