> ## Documentation Index
> Fetch the complete documentation index at: https://developers.authlete.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Update Access Token

> Update an access token.




## OpenAPI

````yaml https://spec.speakeasy.com/authlete/sdk-workspace/authlete-api-explorer-with-code-samples post /api/{serviceId}/auth/token/update
openapi: 3.0.3
info:
  title: Authlete API
  description: ''
  version: 3.0.16
  license:
    name: Apache 2.0
    url: https://www.apache.org/licenses/LICENSE-2.0.html
servers:
  - description: 🇺🇸 US Cluster
    url: https://us.authlete.com
  - description: 🇯🇵 Japan Cluster
    url: https://jp.authlete.com
  - description: 🇪🇺 Europe Cluster
    url: https://eu.authlete.com
  - description: 🇧🇷 Brazil Cluster
    url: https://br.authlete.com
security:
  - bearer: []
tags:
  - name: Service Management
    description: >-
      API endpoints for managing services, including creation, update, and
      deletion of services.
    x-tag-expanded: false
  - name: Client Management
    description: >-
      API endpoints for managing OAuth clients, including creation, update, and
      deletion of clients.
    x-tag-expanded: false
  - name: Authorization Endpoint
    description: API endpoints for implementing OAuth 2.0 Authorization Endpoint.
    x-tag-expanded: false
  - name: Pushed Authorization Endpoint
    description: >-
      API endpoints for implementing OAuth 2.0 Pushed Authorization Requests
      (PAR).
    x-tag-expanded: false
  - name: Token Endpoint
    description: API endpoints for implementing OAuth 2.0 Token Endpoint.
    x-tag-expanded: false
  - name: Token Operations
    description: >-
      API endpoints for various token related operations, including creating,
      revoking and deleting access_tokens with specified scopes.
    x-tag-expanded: false
  - name: Introspection Endpoint
    description: API endpoints for implementing OAuth 2.0 Introspection Endpoint.
    x-tag-expanded: false
  - name: Revocation Endpoint
    description: API endpoint for implementing OAuth 2.0 Revocation Endpoint.
    x-tag-expanded: false
  - name: UserInfo Endpoint
    description: API endpoints for implementing OpenID Connect UserInfo Endpoint.
    x-tag-expanded: false
  - name: JWK Set Endpoint
    description: API endpoints for to generate JSON Web Key Set (JWKS) for a service.
    x-tag-expanded: false
  - name: Discovery Endpoint
    description: API endpoints for implementing OpenID Connect Discovery.
    x-tag-expanded: false
  - name: Configuration Endpoint
    description: API endpoint for accessing configuration settings for a service.
    x-tag-expanded: false
  - name: Dynamic Client Registration
    description: API endpoints for implementing OAuth 2.0 Dynamic Client Registration.
    x-tag-expanded: false
  - name: CIBA
    description: >-
      API endpoints for implementing Client-Initiated Backchannel Authentication
      (CIBA).
    x-tag-expanded: false
  - name: Grant Management Endpoint
    description: >-
      API endpoint for implementing OAuth 2.0 grants, including grant management
      actions like updating and revoking grants.
    x-tag-expanded: false
  - name: Jose Object
    description: API endpoints for JOSE objects.
    x-tag-expanded: false
  - name: Device Flow
    description: API endpoints for implementing OAuth 2.0 Device Flow
    x-tag-expanded: false
  - name: Federation Endpoint
    description: API endpoints for implementing OpenID Federation using Authlete.
    x-tag-expanded: false
  - name: Verifiable Credential Issuer
    description: >-
      API endpoints for implementing and running a Verifiable Credential Issuer
      (VCI).
    x-tag-expanded: false
  - name: Hardware Security Key
    description: API endpoints for managing hardware security keys (HSK).
    x-tag-expanded: false
  - name: Utility Endpoints
    description: API endpoints for various utility operations.
    x-tag-expanded: false
  - name: Native SSO
    description: API endpoints for Native SSO
    x-tag-expanded: false
paths:
  /api/{serviceId}/auth/token/update:
    post:
      tags:
        - Token Operations
      summary: Update Access Token
      description: |
        Update an access token.
      operationId: auth_token_update_api
      parameters:
        - in: path
          name: serviceId
          description: A service ID.
          schema:
            type: string
          required: true
      requestBody:
        required: true
        content:
          application/json:
            schema:
              $ref: '#/components/schemas/token_update_request'
            example:
              accessToken: Z5a40U6dWvw2gMoCOAFbZcM85q4HC0Z--0YKD9-Nf6Q
              scopes:
                - history.read
          application/x-www-form-urlencoded:
            schema:
              $ref: '#/components/schemas/token_update_request'
      responses:
        '200':
          description: Token updated successfully
          content:
            application/json:
              schema:
                $ref: '#/components/schemas/token_update_response'
              example:
                resultCode: A135001
                resultMessage: '[A135001] Updated the access token successfully.'
                accessToken: Z5a40U6dWvw2gMoCOAFbZcM85q4HC0Z--0YKD9-Nf6Q
                accessTokenExpiresAt: 1642048149000
                action: OK
                scopes:
                  - history.read
                tokenType: Bearer
          links:
            token_issue:
              $ref: '#/components/links/token_issue'
        '400':
          $ref: '#/components/responses/400'
        '401':
          $ref: '#/components/responses/401'
        '403':
          $ref: '#/components/responses/403'
        '500':
          $ref: '#/components/responses/500'
      x-codeSamples:
        - lang: typescript
          label: Typescript (SDK)
          source: |-
            import { Authlete } from "@authlete/typescript-sdk";

            const authlete = new Authlete({
              bearer: process.env["AUTHLETE_BEARER"] ?? "",
            });

            async function run() {
              const result = await authlete.token.management.update({
                serviceId: "<id>",
                tokenUpdateRequest: {
                  accessToken: "Z5a40U6dWvw2gMoCOAFbZcM85q4HC0Z--0YKD9-Nf6Q",
                  scopes: [
                    "history.read",
                  ],
                },
              });

              console.log(result);
            }

            run();
        - lang: ruby
          label: Ruby (SDK)
          source: >-
            require 'authlete_ruby_sdk'


            Models = ::Authlete::Models

            s = ::Authlete::Client.new(
              bearer: '<YOUR_BEARER_TOKEN_HERE>'
            )

            res = s.token_management.update(service_id: '<id>',
            token_update_request: Models::Components::TokenUpdateRequest.new(
              access_token: 'Z5a40U6dWvw2gMoCOAFbZcM85q4HC0Z--0YKD9-Nf6Q',
              scopes: [
                'history.read',
              ]
            ))


            unless res.token_update_response.nil?
              # handle response
            end
        - lang: go
          label: Go (SDK)
          source: "package main\n\nimport(\n\t\"context\"\n\t\"os\"\n\tauthlete \"github.com/authlete/authlete-go-sdk\"\n\t\"github.com/authlete/authlete-go-sdk/models/components\"\n\t\"log\"\n)\n\nfunc main() {\n    ctx := context.Background()\n\n    s := authlete.New(\n        authlete.WithSecurity(os.Getenv(\"AUTHLETE_BEARER\")),\n    )\n\n    res, err := s.Token.Management.Update(ctx, \"<id>\", components.TokenUpdateRequest{\n        AccessToken: authlete.Pointer(\"Z5a40U6dWvw2gMoCOAFbZcM85q4HC0Z--0YKD9-Nf6Q\"),\n        Scopes: []string{\n            \"history.read\",\n        },\n    })\n    if err != nil {\n        log.Fatal(err)\n    }\n    if res.TokenUpdateResponse != nil {\n        // handle response\n    }\n}"
      x-code-samples:
        - lang: shell
          label: curl
          source: >
            curl -v -X POST
            https://us.authlete.com/api/21653835348762/auth/token/update \

            -H 'Content-Type:application/json' \

            -H 'Authorization: Bearer
            V5a40R6dWvw2gMkCOBFdZcM95q4HC0Z-T0YKD9-nR6F' \

            -d '{ "accessToken": "Z5a40U6dWvw2gMoCOAFbZcM85q4HC0Z--0YKD9-Nf6Q",
            "scopes": [ "history.read" ] }'
        - lang: java
          label: java
          source: |
            AuthleteConfiguration conf = ...;
            AuthleteApi api = AuthleteApiFactory.create(conf);

            TokenUpdateRequest req = new TokenUpdateRequest();
            req.setAccessToken("JDGiiM9PuWT63FIwGjG9eYlGi-aZMq6CQ2IB475JUxs");
            req.setScopes({ "history.read" });

            api.tokenUpdate(req);
        - lang: python
          source: |
            conf = ...
            api = AuthleteApiImpl(conf)

            req = TokenUpdateRequest()
            req.accessToken = 'JDGiiM9PuWT63FIwGjG9eYlGi-aZMq6CQ2IB475JUxs'
            req.scopes = [ 'history.read' ]

            api.tokenUpdate(req)
components:
  schemas:
    token_update_request:
      type: object
      properties:
        accessToken:
          type: string
          description: |
            An access token.
        accessTokenExpiresAt:
          type: integer
          format: int64
          description: >
            A new date at which the access token will expire in milliseconds
            since the Unix epoch (1970-01-01).

            If the `accessTokenExpiresAt` request parameter is not included in a
            request or its value is 0

            (or negative), the expiration date of the access token is not
            changed.
        scopes:
          type: array
          items:
            type: string
          description: >
            A new set of scopes assigned to the access token. Scopes that are
            not supported by the service

            and those that the client application associated with the access
            token is not allowed to request

            are ignored on the server side. If the `scopes` request parameter is
            not included in a request or

            its value is `null`, the scopes of the access token are not changed.
            Note that `properties` parameter

            is accepted only when `Content-Type` of the request is
            `application/json`, so don't use `application/x-www-form-urlencoded`

            if you want to specify `properties`.
        properties:
          type: array
          items:
            $ref: '#/components/schemas/property'
          description: >
            A new set of properties assigned to the access token. If the
            `properties` request parameter is

            not included in a request or its value is null, the properties of
            the access token are not changed.
        accessTokenExpiresAtUpdatedOnScopeUpdate:
          type: boolean
          description: >
            A boolean request parameter which indicates whether the API attempts
            to update the expiration

            date of the access token when the scopes linked to the access token
            are changed by this request.
        accessTokenHash:
          type: string
          description: >
            The hash of the access token value. Used when the hash of the token
            is known (perhaps from lookup)

            but the value of the token itself is not. The value of the
            `accessToken` parameter takes precedence.
        accessTokenValueUpdated:
          type: boolean
          description: >
            A boolean request parameter which indicates whether to update the
            value of the access token in

            the data store. If this parameter is set to `true` then a new access
            token value is generated

            by the server and returned in the response.
        accessTokenPersistent:
          type: boolean
          description: >
            The flag which indicates whether the access token expires or not. By
            default, all access tokens

            expire after a period of time determined by their service. If this
            request parameter is `true`

            then the access token will not automatically expire and must be
            revoked or deleted manually at

            the service.


            If this request parameter is `true`, the `accessTokenExpiresAt`
            request parameter is ignored.

            If this request parameter is `false`, the `accessTokenExpiresAt`
            request parameter is processed

            normally.
        certificateThumbprint:
          type: string
          description: >
            The thumbprint of the MTLS certificate bound to this token. If this
            property is set, a certificate

            with the corresponding value MUST be presented with the access token
            when it is used by a client.

            The value of this property must be a SHA256 certificate thumbprint,
            base64url encoded.
        dpopKeyThumbprint:
          type: string
          description: >
            The thumbprint of the public key used for DPoP presentation of this
            token. If this property is

            set, a DPoP proof signed with the corresponding private key MUST be
            presented with the access

            token when it is used by a client. Additionally, the token's
            `token_type` will be set to 'DPoP'.
        authorizationDetails:
          $ref: '#/components/schemas/authz_details'
        forExternalAttachment:
          type: boolean
          description: |
            the flag which indicates whether the access token is for an external
            attachment.
        refreshTokenExpiresAt:
          type: integer
          format: int64
          description: >
            A new date at which the access token will expire in milliseconds
            since the Unix epoch (1970-01-01).

            If the `refreshTokenExpiresAt` request parameter is not included in
            a request or its value is 0

            (or negative), the expiration date of the refresh token is not
            changed.
        refreshTokenExpiresAtUpdatedOnScopeUpdate:
          type: boolean
          description: >
            A boolean request parameter which indicates whether the API attempts
            to update the expiration

            date of the refresh token when the scopes linked to the refresh
            token are changed by this request.
        tokenId:
          type: string
          description: |
            The token identifier.
    token_update_response:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
        action:
          type: string
          enum:
            - INTERNAL_SERVER_ERROR
            - BAD_REQUEST
            - FORBIDDEN
            - NOT_FOUND
            - OK
          description: >-
            The next action that the authorization server implementation should
            take.
        accessToken:
          type: string
          description: The access token which has been specified by the request.
        accessTokenExpiresAt:
          type: integer
          format: int64
          description: |
            The date at which the access token will expire.
        properties:
          type: array
          items:
            $ref: '#/components/schemas/property'
          description: |
            The extra properties associated with the access token.
        scopes:
          type: array
          items:
            type: string
          description: |
            The scopes associated with the access token.
        authorizationDetails:
          $ref: '#/components/schemas/authz_details'
        tokenType:
          type: string
          description: |
            The token type associated with the access token.
        forExternalAttachment:
          type: boolean
          description: |
            the flag which indicates whether the access token is for an external
            attachment.
        tokenId:
          type: string
          description: |
            Set the unique token identifier.
        refreshTokenExpiresAt:
          type: integer
          format: int64
          description: >
            The datetime at which the newly issued refresh token will expire.

            The value is represented in milliseconds since the Unix epoch
            (1970-01-01).
    property:
      type: object
      properties:
        key:
          type: string
          description: The key part.
        value:
          type: string
          description: The value part.
        hidden:
          type: boolean
          description: >
            The flag to indicate whether this property hidden from or visible to
            client applications.

            If `true`, this property is hidden from client applications.
            Otherwise, this property is visible to client applications.
    authz_details:
      type: object
      description: >
        The authorization details. This represents the value of the
        `authorization_details`

        request parameter in the preceding device authorization request which is
        defined in

        "OAuth 2.0 Rich Authorization Requests".
      properties:
        elements:
          type: array
          items:
            $ref: '#/components/schemas/authorization_details_element'
          description: |
            Elements of this authorization details.
    result:
      type: object
      properties:
        resultCode:
          type: string
          description: The code which represents the result of the API call.
        resultMessage:
          type: string
          description: A short message which explains the result of the API call.
    authorization_details_element:
      type: object
      required:
        - type
      properties:
        type:
          type: string
          description: >
            The type of this element.


            From _"OAuth 2.0 Rich Authorization Requests"_: _"The type of
            authorization data as a string.

            This field MAY define which other elements are allowed in the
            request. This element is REQUIRED."_


            This property is always NOT `null`.
        locations:
          type: array
          items:
            type: string
          description: >
            The resources and/or resource servers. This property may be `null`.


            From _"OAuth 2.0 Rich Authorization Requests"_: _"An array of
            strings representing the location of

            the resource or resource server. This is typically composed of
            URIs."_


            This property may be `null`.
        actions:
          type: array
          items:
            type: string
          description: >
            The actions.


            From _"OAuth 2.0 Rich Authorization Requests"_: _"An array of
            strings representing the kinds of actions

            to be taken at the resource. The values of the strings are
            determined by the API being protected."_


            This property may be `null`.
        dataTypes:
          type: array
          items:
            type: string
          description: >
            From _"OAuth 2.0 Rich Authorization Requests"_: _"An array of
            strings representing the kinds of data being requested

            from the resource."_


            This property may be `null`.
        identifier:
          type: string
          description: >
            The identifier of a specific resource.

            From _"OAuth 2.0 Rich Authorization Requests"_: _"A string
            identifier indicating a specific resource available at the API."_


            This property may be `null`.
        privileges:
          type: array
          items:
            type: string
          description: >
            The types or levels of privilege.

            From "OAuth 2.0 Rich Authorization Requests": _"An array of strings
            representing the types or

            levels of privilege being requested at the resource."_


            This property may be `null`.
        otherFields:
          type: string
          description: >
            The RAR request in the JSON format excluding the pre-defined
            attributes such as `type` and `locations`.

            The content and semantics are specific to the deployment and the use
            case implemented.
  responses:
    '400':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001201
            resultMessage: '[A001201] /auth/authorization, TLS must be used.'
    '401':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001202
            resultMessage: '[A001202] /auth/authorization, Authorization header is missing.'
    '403':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001215
            resultMessage: >-
              [A001215] /auth/authorization, The client (ID = 26837717140341) is
              locked.
    '500':
      description: ''
      content:
        application/json:
          schema:
            $ref: '#/components/schemas/result'
          example:
            resultCode: A001101
            resultMessage: '[A001101] /auth/authorization, Authlete Server error.'
  securitySchemes:
    bearer:
      type: http
      scheme: bearer
      bearerFormat: JWT
      description: >
        Authenticate every request with a **Service Access Token** or
        **Organization Token**.

        Set the token value in the `Authorization: Bearer <token>` header.


        **Service Access Token**: Scoped to a single service. Use when
        automating service-level configuration or runtime flows.


        **Organization Token**: Scoped to the organization; inherits permissions
        across services. Use for org-wide automation or when managing multiple
        services programmatically.


        Both token types are issued by the Authlete console or provisioning
        APIs.

````