> For the complete documentation index, see [llms.txt](https://docs.cotter.app/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.cotter.app/getting-access-token/getting-the-tokens/get-tokens-during-authentication.md).

# Get Tokens during Authentication

When a user logs in to your application using the **Sign in with Email/Phone** or the **Sign in with Device** method, Cotter will return OAuth tokens in the form of JWT Tokens.

* For **Sign in with Email/Phone:** The `authentication_method` = `OTP`
* For **Sign in with Device:** The `authentication_method` = `TRUSTED_DEVICE`

{% tabs %}
{% tab title="JS/HTML" %}
You will receive the access token when using these features:

{% content-ref url="/pages/-M0ROJn7tosL9qeumqFd" %}
[Sign In with Email/Phone Number](/sdk-reference/web/web-sdk-verify-email-phone.md)
{% endcontent-ref %}

{% content-ref url="/pages/-MCk3X5Dh4Fkxp20D4Rt" %}
[Sign In with WebAuthn](/sdk-reference/web/sign-in-with-webauthn.md)
{% endcontent-ref %}

{% hint style="success" %}
The JS SDK **automatically store your tokens securely**
{% endhint %}
{% endtab %}

{% tab title="React Native" %}
You will get an access token when using the following features:

{% content-ref url="/pages/-M2kTuM6W90CT9IpIxHq" %}
[Sign In with Device](/sdk-reference/react-native/react-native-sdk-passwordless-login.md)
{% endcontent-ref %}

{% content-ref url="/pages/-M1dk\_Rosjlkj52Hq\_6R" %}
[Sign In with Email/Phone Number](/sdk-reference/react-native/react-native-sdk-verify-email-phone.md)
{% endcontent-ref %}

{% hint style="success" %}
The React Native SDK **automatically** **store your tokens securely**
{% endhint %}
{% endtab %}

{% tab title="Flutter" %}
You will get an access token when using the following features:

{% content-ref url="/pages/-M9angupK73fWUZjM7fe" %}
[Sign In with Device](/sdk-reference/flutter/sign-in-with-device.md)
{% endcontent-ref %}

{% content-ref url="/pages/-MATH96wMixRR82bWQJJ" %}
[Sign in with Email/Phone Number](/sdk-reference/flutter/sign-in-with-email-phone-number.md)
{% endcontent-ref %}

{% hint style="success" %}
The Flutter SDK **automatically** **store your tokens securely**
{% endhint %}
{% endtab %}

{% tab title="Android" %}
You will get an access token when using the following features:

{% content-ref url="/pages/-MCxyo3ix-jqWDQysF0g" %}
[Sign In with Device](/sdk-reference/android/sign-in-with-device.md)
{% endcontent-ref %}

{% content-ref url="/pages/-M0et2D8qa-mVoDh-tjp" %}
[Sign In with Email/Phone Number](/sdk-reference/android/android-sdk-1.md)
{% endcontent-ref %}
{% endtab %}

{% tab title="API For Mobile Apps" %}
Using the [API for Mobile Apps](/sdk-reference/api-for-other-mobile-apps.md), you would follow this guide to [get the identity of the user.](/sdk-reference/api-for-other-mobile-apps/api-for-mobile-apps.md#step-3-request-tokens-and-identity) When the user's email or phone number is successfully verified, [you'll receive information about the user and a signature from Cotter.](/sdk-reference/api-for-other-mobile-apps/api-for-mobile-apps.md#response)

To also receive OAuth Tokens, add a query parameter `oauth_token=true` in the http request:

```
https://www.cotter.app/api/v0/verify/get_identity?oauth_token=true
```

The full request would be:

```
curl -XPOST \
-H 'Content-type: application/json' \
-H 'API_KEY_ID: <api_key_id>' \
-d '{
  "code_verifier": "<code_verifier>",
  "authorization_code": "<authorization_code>",
  "challenge_id": <challenge_id>,
  "redirect_url": "<redirect_url>"
}' 'https://www.cotter.app/api/v0/verify/get_identity?oauth_token=true'
```

You'll get the following response:

{% code title="JSON Response" %}

```javascript
{
  "identifier": {
    "ID": "2ddc26f6-f392-4d7e-8607-1f57d41da045",
    "created_at": "2020-04-05T04:50:55.931771Z",
    "deleted_at": null,
    "device_name": "Mozilla/5.0 (iPhone; CPU iPhone OS 13_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.1 Mobile/15E148 Safari/604.1",
    "device_type": "BROWSER",
    "expiry": "2020-05-07T03:34:58.729745Z",
    "identifier": "hello@gmail.com",
    "identifier_type": "EMAIL",
    "public_key": "FvozWVGHo9lWE5ilLOF...",
    "timestamp": "2020-04-07T03:34:58.729745Z",
    "update_at": "2020-04-07T03:34:58.733779Z"
  },
  "token": { // You can ignore this if you're using the oauth_token 
    "expire_at": "1588822498",
    "identifier": "hello@gmail.com",
    "identifier_id": "2ddc26f6-f392-4d7e-8607-1f57d41da045",
    "identifier_type": "EMAIL",
    "receiver": "<your API KEY ID>",
    "signature": "XIbztHLKQSqzbnuBgyC+GfAK...",
    "timestamp": "1586230498"
  },
  "oauth_token": {  // 👈 NEW OAuth Tokens 👈
    "access_token": "eyJhbGciOiJFUz...",
    "auth_method": "OTP",
    "expires_in": 3600,
    "id_token": "eyJhbGciOiJFUz...",
    "refresh_token": "94:qv2SAJN5u2u...",
    "token_type": "Bearer"
  }
}
```

{% endcode %}
{% endtab %}

{% tab title="Other SDKs (coming soon)" %}
We'll add support for the other SDKs soon 😉. Stay tuned!
{% endtab %}
{% endtabs %}

{% hint style="warning" %}
**Tokens must be stored securely within your application.** Use [Android Keystore](https://developer.android.com/training/articles/keystore) for Android and [iOS KeyChain](https://developer.apple.com/documentation/security/keychain_services) for iOS apps.
{% endhint %}

## Getting and Removing tokens from the Storage

You need to pass the `access_token` to your backend server on every API calls. You also need to remove the tokens from storage to log out your users. Check out how to do that here:

{% content-ref url="/pages/-M4I5Ed9v0BbC7OxzSFn" %}
[Storing and Removing Tokens](/getting-access-token/storing-and-removing-tokens.md)
{% endcontent-ref %}

## Renewing Expired Tokens

Access tokens and ID tokens expires in 1 hour. When they're expired, you need to use the `refresh_token` to get new tokens. Check out how to renew expired tokens:

{% content-ref url="/pages/-M4I0B0i0yghkR8yjphX" %}
[Renewing Expired Tokens](/getting-access-token/renewing-expired-tokens.md)
{% endcontent-ref %}
