In the refresh-token api (/auth/refresh-token), there needs to be a check for expiry of the refresh token. https://github.com/vnovick/graphql-jwt-tutorial/blob/58ebfe1ed6a253fa6b6198ca14001c5eeaa7fbf8/backend/src/auth/index.js#L220