my understanding about token is jwt is only return accesstoken that doesnot contain username ,email such without password ,but refresh token is genarated by jwt or backend my understanding is it is a random string generated by backend so next dought what is inside the refresh token
Hi @jefijefin8
Welcome to the Auth0 Community!
Refresh Tokens are opaque and contain no readable user data.
Unlike an ID Token (which is a JWT containing readable user information), an Auth0 Refresh Token is an opaque string — a randomly generated token created by Auth0's backend. It serves as a secure reference to your session stored in Auth0's database, not as a container for user data.
User data is stored in the ID Token, which your frontend receives and can decode.
Key Differences:
| Token Type | Format | Contains User Data | Purpose |
|---|---|---|---|
| ID Token | JWT (readable) | Yes | Identifies the authenticated user; contains claims like name, email, profile |
| Access Token | JWT or Opaque | No | Authorizes API access; not meant for user identification |
| Refresh Token | Opaque (unreadable) | No | Obtains new tokens without re-authentication |
Where to Find User Data:
- ID Token: Decode this JWT to access user claims (name, email, profile picture, custom claims, etc.)
- Refresh Token: Cannot be decoded; use it only to request new tokens
- Access Token: Use to call APIs; if you need user data, decode the ID Token instead
Example:
When a user logs in, Auth0 returns:
- ID Token:
eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...(decodable; contains user info) - Access Token:
eyJhbGciOiJSUzI1NiIsInR5cCI6IkpXVCJ9...(may be JWT or opaque) - Refresh Token:
U1olGgd...tmu8nCH(opaque; cannot be decoded)
To access user information after login, decode the ID Token, not the Refresh Token.
Kind Regards,
Nik