# Update ID Token

**URL:** <https://forum.keycloak.org/t/update-id-token/24987>\
**Category:** Miscellanaeous\
**Tags:** oidc\
**Created:** [March 11, 2024, 10:12am UTC](https://forum.keycloak.org/t/update-id-token/24987 "2024-03-11T10:12:08Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![simoncarbajal](https://avatars.discourse-cdn.com/v4/letter/s/e47c2d/32.png) [@simoncarbajal](https://forum.keycloak.org/u/simoncarbajal)\
**Post date:** [March 11, 2024, 10:12am UTC](https://forum.keycloak.org/t/update-id-token/24987/1 "2024-03-11T10:12:08Z")

</div>

When a user logs in (through Keycloak, with OpenID Connect using the authorization code flow), Keycloak creates an [ID token](https://connect2id.com/learn/openid-connect#id-token) and stores it as a JWT in a cookie.

Now, let’s suppose while the user is already logged in, he/she changes some data like his/her phone number which also happens to be stored in the ID Token.  
This data is changed outside Keycloak and eventually changed in Keycloak’s database. After this update is performed, if the user logs out and logs in again, the ID token is updated with the new data (a phone number in this particular case).

Now, is there a way update the ID token with the new data, without requiring to logout and login again?

Thank you very much for your help!

---

<div class="post-metadata">

**Author:** ![embesozzi](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/embesozzi/32/12390_2.png) [@embesozzi](https://forum.keycloak.org/u/embesozzi)\
**Post date:** [March 11, 2024, 12:09pm UTC](https://forum.keycloak.org/t/update-id-token/24987/2 "2024-03-11T12:09:07Z")

</div>

One easy solution could be to use the **Refresh Token** to obtain new tokens.

---

<div class="post-metadata">

**Author:** ![appsec\_hero](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/appsec_hero/32/9788_2.png) [@appsec\_hero](https://forum.keycloak.org/u/appsec_hero)\
**Post date:** [March 11, 2024, 10:39pm UTC](https://forum.keycloak.org/t/update-id-token/24987/3 "2024-03-11T22:39:33Z")

</div>

And you can also call the [userinfo endpoint](https://openid.net/specs/openid-connect-core-1_0.html#UserInfo) which will returns the updated claims about the authenticated user.  
You can specify which claims will appear in the ID Token and/or the userinfo endpoint.
