How to use refresh tokens with a self-hosted login

Which part? The security risks or how to implement?