JWT Authentication with refresh token

Viewed 52

i'm working on JWT refresh token and i'm trying to understand why is a refresh token needed for short lived JWT token. Understand that refresh token will be used to renew the short lived access token once expired as it prevent attacker from accessing the web api in case long lived access token is used. However, this the issue that is puzzling me, if an attacker can get the access token, wouldn't he will be able to call the refresh token API to get another access token, that case, won't the refresh token redundant?

0 Answers
Related