October 1, 2026
As part of our commitment to maintaining the highest security and compliance standards, we will soon be updating our authentication service configuration to increase the length and entropy of our refresh tokens.
What is changing?
We are increasing the cryptographic entropy of our issued Refresh Tokens. As a result, the string length of newly issued Refresh Tokens will increase beyond the current ~45-character baseline.
Why is this changing?
Higher entropy ensures that refresh tokens are even more resilient against brute-force attacks and key-guessing attempts. Auth0's lifecycle policies explicitly note that token formats and lengths are non-deterministic and subject to change without deprecation notices. However, we want to proactively notify you to ensure a seamless transition for your integrations.
Who is impacted?
You may be impacted if your client applications, APIs, or database schemas perform any of the following:
- Hardcoded length checks: Validating that a token string is strictly 45 characters long.
- Fixed-size database storage: Storing refresh tokens in fixed-width columns (e.g., VARCHAR(45) or CHAR(45)).
- Regex validation: Employing regex patterns that enforce a maximum length limit.
Recommended Actions
- Remove strict length validations: Treat refresh tokens as variable-length opaque strings.
- Update database storage: Ensure columns storing refresh tokens use variable/flexible string sizes.
Timeline
Newly minted refresh tokens will start to have bigger sizes in the coming weeks. Existing active sessions and existing refresh tokens will remain valid until expired or revoked; only newly issued tokens will reflect the updated length.
Questions?
If you have any questions or require support during this transition, please reach out to Support








































































You can learn more about Templates for Actions from our 




Did someone order up one Dark Mode Browser extra Hot! Feel free to dim the lights; Teams Dashboard now supports dark mode.













Once enabled, the custom database action script will be passed an extra parameter, 
































