curl --request POST \
--url https://oauth2-{dc}.moengage.com/v1/oauth/refresh \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=refresh_token \
--data client_id=YOUR_WORKSPACE_ID \
--data refresh_token=550e8400-e29b-41d4-a716-446655440000{
"status": "SUCCESS",
"data": {
"access_token": "eyJhbGciOiJSUzI1NiJ9.<new-payload>.<new-signature>",
"token_type": "Bearer",
"expires_in": 900
}
}{
"status": "FAILURE",
"error_type": "ER021",
"reason": "refresh_token is required."
}{
"status": "FAILURE",
"error_type": "ER010",
"reason": "Refresh token is not valid."
}{
"status": "FAILURE",
"error_type": "<string>",
"reason": "<string>"
}{
"status": "FAILURE",
"error_type": "RATE_LIMIT_EXCEEDED",
"reason": "Too many requests."
}Refresh Access Token
Exchange a refresh token for a new access token. The refresh request does not use your API key.
A refresh returns a new access token and preserves your existing refresh token. Continue using that refresh token until the token reaches its 30-day expiry, and then call Generate Access Token again with your client_id and client_secret.
For the end-to-end integration, refer to OAuth 2.0 Overview. For the recommended refresh timing, refer to Recommended Practices.
curl --request POST \
--url https://oauth2-{dc}.moengage.com/v1/oauth/refresh \
--header 'Content-Type: application/x-www-form-urlencoded' \
--data grant_type=refresh_token \
--data client_id=YOUR_WORKSPACE_ID \
--data refresh_token=550e8400-e29b-41d4-a716-446655440000{
"status": "SUCCESS",
"data": {
"access_token": "eyJhbGciOiJSUzI1NiJ9.<new-payload>.<new-signature>",
"token_type": "Bearer",
"expires_in": 900
}
}{
"status": "FAILURE",
"error_type": "ER021",
"reason": "refresh_token is required."
}{
"status": "FAILURE",
"error_type": "ER010",
"reason": "Refresh token is not valid."
}{
"status": "FAILURE",
"error_type": "<string>",
"reason": "<string>"
}{
"status": "FAILURE",
"error_type": "RATE_LIMIT_EXCEEDED",
"reason": "Too many requests."
}Rate Limit
This endpoint allows 30 requests per 10 minutes and 5 requests per minute. Both limits apply perclient_id and client_secret pair. A 429 response includes a Retry-After header that gives the number of seconds to wait.
Refresh proactively, a few minutes before the access token expires, instead of waiting for an ER008 on an API call. Use the expires_in value returned with the access token to schedule the refresh.Body
The form-encoded parameters for the refresh token grant.
The OAuth 2.0 grant type. The supported value is refresh_token.
refresh_token Your Workspace ID. The value must match the Workspace ID that the refresh token was issued to, or the request fails with ER013.
The refresh token returned by Generate Access Token. The refresh token is valid for 30 days.