--- title: "Getting a Refresh Token" slug: "getting-a-refresh-token" updated: 2025-10-21T03:00:04Z published: 2025-10-21T03:00:04Z canonical: "docs.processmaker.com/getting-a-refresh-token" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.processmaker.com/llms.txt > Use this file to discover all available pages before exploring further. # Getting a Refresh Token This guide walks you through the steps of refreshing an access token for making RESTful API calls to ProcessMaker. Access tokens typically have a limited lifespan, and once they expire, they need to be refreshed using a refresh token. This guide assumes you already have a refresh token. If not, refer to the [How to Get an Access Token](/v1-api/apidocs/getting-an-access-token) guide. ## Client Application 🔗 [Creating a Client Application](/v1-api/apidocs/creatingclientapplicationpm) ## Choose Your Tutorial PythonNode.jsPostmancURL **Step 1: Install Necessary Python Libraries** Before starting, ensure you have the necessary Python libraries installed. You'll need `requests` for making HTTP requests. Install them via pip: ```plaintext pip install requests ``` **Step 2: Refresh the Access Token** Use the following Python code to refresh your access token: ```python import requests # Define the token endpoint token_url = "https://.processmaker.net/oauth/token" # Define the payload payload = {    "grant_type": "refresh_token",    "refresh_token": "",    "client_id": "",    "client_secret": "" } # Make the POST request response = requests.post(token_url, data=payload) token_info = response.json() # Print the new access token print(f'New Access Token: {token_info["access_token"]}') ``` > [!WARNING] > Don't forget to replace the following: > > - `<your-instance>` with your actual ProcessMaker instance URL. > - `<your-refresh-token>` with the refresh token you received when you first obtained your access token. > - `<your-client-id>` and `<your-client-secret>` with the client ID and secret of your application. **Step 3: Review the Response** After executing the script, you should receive a new access token and possibly a new refresh token. Store these securely, as you'll need the access token for future API requests and the refresh token for future token refreshes. **Conclusion** Refreshing your access token is an essential step in maintaining uninterrupted access to the ProcessMaker API. By using Python and the `requests` library, you can easily and efficiently refresh your token. Always ensure you handle your tokens securely, as they are vital for maintaining secure communication with the API. **Step 1: Obtaining the access token** 🔗 [Creating a Client Application](/v1-api/apidocs/creatingclientapplicationpm) **Step 2: Install Necessary Node.js Libraries** Before starting, ensure you have the necessary Node.js libraries installed. You'll need `axios` for making HTTP requests. You can install it via npm: ```plaintext npm install axios ``` **Step 3: Refreshing the Access Token** Use the following Node.js code to refresh your access token: ```node-repl const axios = require('axios'); // Define the token endpoint const token_url = "https://.processmaker.net/oauth/token"; // Define the payload const payload = {    grant_type: "refresh_token",    refresh_token: "",    client_id: "",    client_secret: "" }; // Make the POST request axios.post(token_url, payload)    .then(response => {        console.logNew Access Token: ${response.data.access_token});    })    .catch(error => {        console.error('Error refreshing token:', error.response.data);    }); ``` > [!WARNING] > Don't forget to replace the following: > > - `<your-instance>` with your actual ProcessMaker instance URL. > - `<your-refresh-token>` with the refresh token you received when you first obtained your access token. > - `<your-client-id>` and `<your-client-secret>` with the client ID and secret of your application. **Step 3: Review the Response** After executing the script, you should receive a new access token and possibly a new refresh token. Store these securely, as you'll need the access token for future API requests and the refresh token for future token refreshes. **Conclusion** Refreshing your access token is an essential step in maintaining uninterrupted access to the ProcessMaker API. By using Node.js and the axios library, you can easily and efficiently refresh your token. Always ensure you handle your tokens securely, as they are vital for maintaining secure communication with the API. **Step 1: Obtaining the access token** 🔗 [Creating a Client Application](/v1-api/apidocs/creatingclientapplicationpm) **Step 2: Download and Install Postman** If you haven't already, [download](https://www.postman.com/downloads/) and install Postman from their official website. **Step 3: Create a New Request Tab** Open Postman, click on the **+** button to create a new tab, then click on the **Authorization** tab. **Step 4: Use the Refresh Token Grant Type** For the refresh token grant type, set the following: - **Type**: Choose **OAuth 2.0** from the drop-down. - **Add auth data to**: Choose **Request Headers**. - Configure New Token: - **Token Name:** Any name for your reference. - **Grant Type:** Client Credentials. - **Access Token URL:** The token URL of the OAuth server. - **Refresh Token**: The refresh token you received when you first obtained your access token. - **Client ID:** The client ID of your OAuth application. - **Client Secret:** The client secret of your OAuth application. - **Scope:** The scope of the access request. - **Client Authentication:** Send as Basic Auth header. - Click **Get New Access Token**. The access token will be automatically filled in the **Access Token** field. **Step 5: Making API Requests** After obtaining the access token, Postman automatically adds the `Authorization: Bearer <access-token>` header to your requests. You can now make requests to the API with the access token. > [!NOTE] > **Remember** > > Always protect your client secret, refresh tokens, and access tokens. These grant access to the API and should be treated with the same care as passwords. **Conclusion** That's it! You now know how to refresh an access token using OAuth 2.0 in Postman. Regularly refreshing your access token ensures uninterrupted access to the ProcessMaker API. **Step 1: Obtaining the access token** 🔗 [Creating a Client Application](/v1-api/apidocs/creatingclientapplicationpm) **Step 2: Refreshing the Access Token** Execute the following command in your terminal: ```plaintext curl -X POST "https://.processmaker.net/oauth/token" \     -d "grant_type=refresh_token&refresh_token=&client_id=&client_secret=" ``` Replace: - `<your-instance>` with your actual ProcessMaker instance URL. - `<your-refresh-token>` with the refresh token you received when you first obtained your access token. - `<your-client-id>` and `<your-client-secret>` with the client ID and secret of your application. **Step 3: Review the Response** After executing the command, you should receive a response from the server. This will provide a new access token and possibly a new refresh token. Store these securely, as you'll need the access token for future API requests and the refresh token for future token refreshes. **Conclusion** Refreshing your access token is a crucial step in maintaining uninterrupted access to the ProcessMaker API. By using the `curl` command, you can easily and efficiently refresh your token directly from the command line. Always ensure you handle your tokens securely, as they are vital for maintaining secure communication with the API.