Refresh tokens are getting longer than ~45 characters
- Takes effect
- Not announced
- Published
- 4 Oct 2026
As part of our commitment to maintaining the highest security and compliance standards, we will soon be updating our authentication service configuration to increase the length and entropy of our refresh tokens. ## What is changing? We are increasing the cryptographic entropy of our issued Refresh Tokens. As a result, the string length of newly issued Refresh Tokens will increase beyond the current ~45-character baseline. ## Why is this changing? Higher entropy ensures that refresh tokens are even more resilient against brute-force attacks and key-guessing attempts. [Auth0's lifecycle policies](https://auth0.com/docs/troubleshoot/product-lifecycle#backward-compatible-non-breaking-changes) explicitly note that token formats and lengths are non-deterministic and subject to change without deprecation notices. However, we want to proactively notify you to ensure a seamless transition for your integrations. ## Who is impacted? You may be impacted if your client applications, APIs, or data
Read the vendor's announcement
Get this on your timeline
Add your stack to StackClock and we will remind you before it takes effect, along with your domain, certificate and license expiries.
Start free