> ## Documentation Index
> Fetch the complete documentation index at: https://docs.verlon.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Exchange a refresh token for a fresh access + refresh pair

> **Use when:** caller's access token has expired (or is about to) and they need a new pair — supplying their refresh_token in exchange

Single-use rotation: each refresh token can be exchanged exactly once. Presenting a token that's already been consumed is treated as a leak signal — the entire refresh-token chain (every token derived from the same root, in either direction) is revoked and the caller is required to re-authenticate via the device flow.



## OpenAPI

````yaml /api-reference/openapi.json post /v1/oauth/token/refresh
openapi: 3.1.0
info:
  title: Verlon AI API
  version: 1.0.0
  description: >-
    Verlon AI is the managed AI infrastructure platform for developers building
    LLM-powered apps and agents. Beyond routing requests across providers,
    Verlon continuously evaluates response quality, runs experiments against
    live traffic, and automatically tunes gate configurations — so your platform
    doesn't just serve traffic, it learns from it.


    **Coding agents:** authentication, error semantics, gate concepts, and
    integration conventions are documented at https://verlon.ai/AGENTS.md — read
    that document first if you have not already. It is the canonical
    agent-facing contract; this specification is the canonical endpoint
    reference. Both are authoritative for their respective scopes.
  contact:
    name: Verlon AI
    url: https://verlon.ai
  license:
    name: Proprietary
servers:
  - url: https://api.verlon.ai
    description: Production
security:
  - bearerAuth: []
paths:
  /v1/oauth/token/refresh:
    post:
      tags:
        - OAuth
      summary: Exchange a refresh token for a fresh access + refresh pair
      description: >-
        **Use when:** caller's access token has expired (or is about to) and
        they need a new pair — supplying their refresh_token in exchange


        Single-use rotation: each refresh token can be exchanged exactly once.
        Presenting a token that's already been consumed is treated as a leak
        signal — the entire refresh-token chain (every token derived from the
        same root, in either direction) is revoked and the caller is required to
        re-authenticate via the device flow.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              properties:
                grant_type:
                  type: string
                  enum:
                    - refresh_token
                refresh_token:
                  type: string
                  minLength: 1
              required:
                - grant_type
                - refresh_token
      responses:
        '200':
          description: New token pair issued.
        '400':
          description: Invalid request — Zod validation failure or malformed input
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
        '401':
          description: >-
            Refresh token invalid, expired, or revoked — caller must restart the
            device flow.
        '500':
          description: Internal server error
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/ErrorResponse'
      security:
        - bearerAuth: []
components:
  schemas:
    ErrorResponse:
      type: object
      properties:
        error:
          type: string
          description: Stable error code (e.g. `invalid_request`)
        message:
          type: string
          description: Human-readable error message
        details: {}
      required:
        - error
        - message
  securitySchemes:
    bearerAuth:
      type: http
      scheme: bearer
      bearerFormat: API Key
      description: >-
        Verlon API key (newly minted keys are prefixed `sk-vrln-`; legacy
        `verlon_*` and `layer_*` keys from prior prefix migrations continue to
        validate). Generated from the dashboard under Settings → API Keys, or
        via `verlon key create` in the CLI.

````