What is the difference between an access token and a refresh token?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
The access token is short-lived and sent on every API call.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
contrast on Auth, not two memorised paragraphs.
the developer, then one case where picking wrong hurts.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1The access token is
short-lived and sent on every API call.
- 2The refresh token is
long-lived, stored more carefully, and used only against the token endpoint to mint new access tokens.
- 3If an access token
leaks, the window of abuse is minutes
- 4a stolen refresh token
should be rotatable and revocable.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
The access token is short-lived and sent on every API call. The refresh token is long-lived, stored more carefully, and used only against the token endpoint to mint new access tokens.