# Refresh Token upgrade to offline\_token

**URL:** <https://forum.keycloak.org/t/refresh-token-upgrade-to-offline-token/25665>\
**Category:** Getting advice\
**Created:** [April 19, 2024, 5:12pm UTC](https://forum.keycloak.org/t/refresh-token-upgrade-to-offline-token/25665 "2024-04-19T17:12:22Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![infl00p](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/infl00p/32/4426_2.png) [@infl00p](https://forum.keycloak.org/u/infl00p)\
**Post date:** [April 19, 2024, 5:12pm UTC](https://forum.keycloak.org/t/refresh-token-upgrade-to-offline-token/25665/1 "2024-04-19T17:12:22Z")

</div>

My question is if it is possible to request an offline token using a refresh request and the normal refresh token using offline\_access in the scope of the request?  
I can get an offline token using the authorization request and continue to use it as an refresh token but I want to upgrade existing refresh tokens without having the users to log in again.

I have added the offline\_access in the scope in my refresh request body but I continue to get a normal refresh token. Do I need to change offline\_access to Default in my client configuration?

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [April 19, 2024, 8:34pm UTC](https://forum.keycloak.org/t/refresh-token-upgrade-to-offline-token/25665/2 "2024-04-19T20:34:35Z")

</div>

You can’t. This would also be against the spec, chapter 11 Offline Access: [Final: OpenID Connect Core 1.0 incorporating errata set 2](https://openid.net/specs/openid-connect-core-1_0.html#OfflineAccess)  
The user MUST give consent to issuing an offline token.
