← All vendor deprecations
Auth0Breaking changemedium

Refresh tokens are getting longer than ~45 characters

Takes effect
Not announced
Published
4 Oct 2026

As part of our commitment to maintaining the highest security and compliance standards, we will soon be updating our authentication service configuration to increase the length and entropy of our refresh tokens. ## What is changing? We are increasing the cryptographic entropy of our issued Refresh Tokens. As a result, the string length of newly issued Refresh Tokens will increase beyond the current ~45-character baseline. ## Why is this changing? Higher entropy ensures that refresh tokens are even more resilient against brute-force attacks and key-guessing attempts. [Auth0's lifecycle policies](https://auth0.com/docs/troubleshoot/product-lifecycle#backward-compatible-non-breaking-changes) explicitly note that token formats and lengths are non-deterministic and subject to change without deprecation notices. However, we want to proactively notify you to ensure a seamless transition for your integrations. ## Who is impacted? You may be impacted if your client applications, APIs, or data

Read the vendor's announcement

Get this on your timeline

Add your stack to StackClock and we will remind you before it takes effect, along with your domain, certificate and license expiries.

Start free