Authentication & Authorization Medium technical 1 views 1 min read

What is the difference between an access token and a refresh token?

Peer-reviewed by HireXTech Technical Panel Updated for 2025/2026 hiring Editorial standards
Practise this track
Interviewer Expectations for this Question
01
Core Competency

Assesses fundamental understanding of Authentication & Authorization conventions, runtime behavior, and memory/performance considerations.

02
Evaluation Criteria

Hiring managers look for precision, avoidance of ambiguous jargon, and ability to explain trade-offs under real production conditions.

Comprehensive Model Answer Verified Solution

An access token is short-lived, typically minutes, and is presented to APIs to authorize requests. If it leaks, the exposure window is small. It is usually a JWT so resource servers can verify it without a central lookup.

A refresh token is long-lived and is used only against the authorization server to obtain new access tokens, so the user does not re-authenticate constantly. It is an opaque credential, stored securely server-side or in a protected client store, and should never be sent to resource servers.

POST /token
grant_type=refresh_token&refresh_token=...&client_id=app

Best practices: keep access tokens in memory where possible, rotate refresh tokens on each use, bind them to the client, and revoke the whole chain if a used refresh token is replayed, which signals theft. Store browser tokens in HttpOnly, Secure cookies when feasible rather than localStorage, and always use TLS.

Candidate Response Strategy & Interview Tips

  1. Start with a concise one-sentence summary: Deliver a direct, confident answer first before expanding into nuances.
  2. Demonstrate real-world trade-offs: Discuss where this approach excels and when you would avoid it in production systems.
  3. Discuss complexity & edge cases: Proactively explain time/space complexity or boundary conditions (null values, scale limits).
  4. Prepare for interviewer follow-ups: Technical hiring panels frequently probe deeper into concurrency, backward compatibility, or alternative libraries.
Related Topics & Skills
Spotted an error or have an alternative solution?