Refresh tokens are getting longer than ~45 characters
No date announced · published 4 Oct 2026
As part of our commitment to maintaining the highest security and compliance standards, we will soon be updating our authentication service configuration to increase the length and entropy of our refresh tokens. ## What is changing? We are increasing the cryptographic entropy of our issued Refresh Tokens. As a result, the string length of newly issued Refresh Tokens will increase beyond the current ~45-character baseline. ## Why is this changing? Higher entropy ensures that refresh tokens are even more resilient against brute-force attacks and key-guessing attempts. [Auth0's lifecycle policies](https://auth0.com/docs/troubleshoot/product-lifecycle#backward-compatible-non-breaking-changes) explicitly note that token formats and lengths are non-deterministic and subject to change without deprecation notices. However, we want to proactively notify you to ensure a seamless transition for your integrations. ## Who is impacted? You may be impacted if your client applications, APIs, or data