# Automatically renewing the refresh token

**URL:** <https://forum.heroiclabs.com/t/automatically-renewing-the-refresh-token/3705>\
**Category:** Client Libraries\
**Created:** [March 28, 2023, 5:33pm UTC](https://forum.heroiclabs.com/t/automatically-renewing-the-refresh-token/3705 "2023-03-28T17:33:19Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![NixarnTowerPop](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/nixarntowerpop/32/800_2.png) [@NixarnTowerPop](https://forum.heroiclabs.com/u/NixarnTowerPop)\
**Post date:** [March 28, 2023, 5:33pm UTC](https://forum.heroiclabs.com/t/automatically-renewing-the-refresh-token/3705/1 "2023-03-28T17:33:19Z")

</div>

Currently there’s support to have the Client. AutoRefreshSession but that only refreshes the session token, so if the refresh token has expired those calls will fail.

What would the best strategy there? And if the session token can have an expiry date of something like 1-7 days, what’s a good value for the refresh token? 30 days? I’m think we could re-authenticate every ~15 days and have the refresh token expiry after 30 days. Something like that. But would be glad to get some light shined on what the best practise is. It’s apparently a common thing to have these two tokens but new to me.

Thanks!

---

<div class="post-metadata">

**Author:** ![tom](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/tom/32/676_2.png) [@tom](https://forum.heroiclabs.com/u/tom)\
**Post date:** [March 29, 2023, 8:51am UTC](https://forum.heroiclabs.com/t/automatically-renewing-the-refresh-token/3705/2 "2023-03-29T08:51:23Z")

</div>

Hi @NixarnTowerPop,

We typically recommend a session token expiry time that equals 2-3 times your game’s average play session.

As for refresh tokens, these are typically longer lived but the exact configuration depends entirely on your needs.

Please see our [session documentation](https://heroiclabs.com/docs/nakama/concepts/session/) and specifically our [session management documentation](https://heroiclabs.com/docs/nakama/concepts/session/management/) for more information. You may also want to have a read up on [refresh tokens](https://auth0.com/blog/refresh-tokens-what-are-they-and-when-to-use-them/) and how they’re used to see how they fit into your requirements.

Generally, you use the refresh token to refresh an expired session without requiring the user to re-authenticate. Once both the session and refresh token have expired you should re-authenticate the user again using their credentials.

---

<div class="post-metadata">

**Author:** ![formatCvt](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/formatcvt/32/1127_2.png) [@formatCvt](https://forum.heroiclabs.com/u/formatCvt)\
**Post date:** [July 4, 2023, 3:37pm UTC](https://forum.heroiclabs.com/t/automatically-renewing-the-refresh-token/3705/3 "2023-07-04T15:37:48Z")

</div>

> [@tom](#):
>
> You may also want to have a read up on [refresh tokens](https://auth0.com/blog/refresh-tokens-what-are-they-and-when-to-use-them/) and how they’re used to see how they fit into your requirements.

Hi! What about Refresh token rotation technique from this doc? [What Are Refresh Tokens and How to Use Them Securely](https://auth0.com/blog/refresh-tokens-what-are-they-and-when-to-use-them/#Refresh-Token-Rotation)

---

<div class="post-metadata">

**Author:** ![formatCvt](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/formatcvt/32/1127_2.png) [@formatCvt](https://forum.heroiclabs.com/u/formatCvt)\
**Post date:** [July 9, 2023, 10:01pm UTC](https://forum.heroiclabs.com/t/automatically-renewing-the-refresh-token/3705/4 "2023-07-09T22:01:11Z")

</div>

I’ve make PR for this feature [Add refresh token rotation feature by formatCvt · Pull Request #1051 · heroiclabs/nakama · GitHub](https://github.com/heroiclabs/nakama/pull/1051)

i’ve found possible security issue also, i will send email to support with details
