0Pricing
Flask Academy · Lesson

Refresh Tokens and Expiry

Rotate access tokens without re-login.

Why Tokens Expire

A stolen token is dangerous only while it works. Giving every access token a short expiry shrinks that window of risk. ⏳

The exp Claim

Expiry lives in the token's exp claim, a timestamp. Once the clock passes it, the token is rejected no matter what.

All lessons in this course

  1. Sessions vs Stateless Tokens
  2. Issue Access Tokens on Login
  3. Protect Endpoints with jwt_required
  4. Refresh Tokens and Expiry
← Back to Flask Academy