Prompt
What should I use for user sessions and refresh tokens?
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
For most web or mobile apps, the safest default is:
- User session: server-side session stored in HTTP-only, Secure, SameSite cookies
- Refresh token: also stored in an HTTP-only, Secure cookie if you use JWT access tokens
- Access token: short-lived, usually kept in memory on the client
Recommended setups
1) Traditional web app
Use a server session:
- Session ID in an HTTP-only cookie
- Session data stored server-side in Redis/database/memory store
- Easy revocation, simple security model
This is usually better than JWTs if you control the backend and browser client.
2) SPA + API
Use:
- Short-lived access token: 5–15 minutes
- Refresh token: in HTTP-only cookie
- Rotate refresh tokens on use
- Keep access token in memory, not localStorage
This reduces risk from XSS.
3) Mobile/native app
Use:
- Access token + refresh token
- Store refresh token in the platform secure store:
- iOS Keychain
- Android Keystore / EncryptedSharedPreferences
- Use short-lived access tokens
What to avoid
- localStorage for tokens if you can avoid it
- Long-lived access tokens
- Storing refresh tokens in JavaScript-accessible storage
- Using JWTs as a replacement for sessions unless you need statelessness
My practical recommendation
If you’re unsure, use:
- HTTP-only, Secure, SameSite cookies
- Server-side sessions for browser apps
- If you need token-based auth, use short-lived access tokens + rotating refresh tokens
Rule of thumb
- Need simple logout/revocation? → server sessions
- Need APIs across multiple clients? → access + refresh tokens
- Need browser security? → HTTP-only cookies
If you want, I can give you:
- a recommended architecture, or
- a cookie/session setup example for Express, FastAPI, Django, or Spring.