What is the difference between an access token and a refresh token?
PICTURE THIS: A SENTENCE BECOMES TOKENS
The model does not read letters like humans. It reads these pieces, then predicts the next one.
Simple meaning
An access token is short-lived and sent on each API call.
WHY — Auth instead of guessing?
Why interviewers care about Auth:
contrast on Auth, not two memorised paragraphs.
the developer, then one case where picking wrong hurts.
Name the idea, why it exists, then one short example.
End with when you use it and one common pitfall.
STEPS — What happens with tokens?
Before the model can read a sentence, it goes through these steps:
- 1An access token is
short-lived and sent on each API call.
- 2A refresh token is
longer-lived and used only to mint new access tokens.
- 3Splitting them limits damage
if a stolen access token expires quickly.
- 4Context mix
Attention looks at nearby tokens together.
- 5Next token
The model scores what should come next.
- 6Decode
IDs turn back into readable text.
EXAMPLE — See it in action
Let's see how a real sentence is tokenized (tokens may vary by model):
Note: Actual tokens and IDs depend on the tokenizer (e.g., GPT, Llama, etc.).
Key takeaway
An access token is short-lived and sent on each API call. A refresh token is longer-lived and used only to mint new access tokens.