Prompt
refresh token expired login loop
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
A refresh token expired login loop usually means the app can’t silently re-authenticate anymore, so it keeps trying to use an invalid refresh token and falls back to login repeatedly.
Common causes
- Refresh token lifetime too short or already expired
- Clock skew between client/server
- Refresh token rotation not handled correctly
- Session/state not cleared after refresh failure
- 401 handling logic retries refresh endlessly
- Cookie/storage issue causing the app to keep sending an old token
- Backend invalidated the refresh token (logout, password change, revoke, max sessions, etc.)
Typical fix
When refresh fails with expired / invalid_token:
- Stop retrying refresh
- Clear auth state (access token, refresh token, user session)
- Redirect to login once
- Prevent infinite retry loops with a guard flag or one-time failure handler
Example flow
API request -> 401
try refresh token
if refresh succeeds -> retry original request
if refresh fails due to expiry -> clear tokens -> send user to login
If you’re debugging
Check:
- refresh token expiry time
- whether refresh token is being updated after each refresh
- whether multiple tabs are invalidating each other
- server logs for token revocation/rotation errors
- frontend network trace for repeated
/refreshcalls
If you want, I can help you fix this in a specific stack like React, Next.js, Vue, Angular, Node, Django, Spring, etc.