Token and refresh token sought

my understanding about token is jwt is only return accesstoken that doesnot contain username ,email such without password ,but refresh token is genarated by jwt or backend my understanding is it is a random string generated by backend so next dought what is inside the refresh token

Hi @jefijefin8

Welcome to the Auth0 Community!

Refresh Tokens are opaque and contain no readable user data.

Unlike an ID Token (which is a JWT containing readable user information), an Auth0 Refresh Token is an opaque string — a randomly generated token created by Auth0's backend. It serves as a secure reference to your session stored in Auth0's database, not as a container for user data.

User data is stored in the ID Token, which your frontend receives and can decode.

Key Differences:

Token Type Format Contains User Data Purpose
ID Token JWT (readable) Yes Identifies the authenticated user; contains claims like name, email, profile
Access Token JWT or Opaque No Authorizes API access; not meant for user identification
Refresh Token Opaque (unreadable) No Obtains new tokens without re-authentication

Where to Find User Data:

  • ID Token: Decode this JWT to access user claims (name, email, profile picture, custom claims, etc.)
  • Refresh Token: Cannot be decoded; use it only to request new tokens
  • Access Token: Use to call APIs; if you need user data, decode the ID Token instead

Example:

When a user logs in, Auth0 returns:

  • ID Token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9... (decodable; contains user info)
  • Access Token: eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9... (may be JWT or opaque)
  • Refresh Token: U1olGgd...tmu8nCH (opaque; cannot be decoded)

To access user information after login, decode the ID Token, not the Refresh Token.

Kind Regards,
Nik