Lifetime of the Okta Minted JSON Web Tokens (JWT)
Last Updated:
Overview
The default and configurable lifetimes of Okta-minted JSON Web Tokens (JWT) vary depending on the authorization server type. The built-in Org Authorization Server uses hard-coded token lifetimes, while Custom Authorization Servers allow configurable token lifetimes within specific ranges.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OpenID Connect / OAuth 2.0 applications
- API Access Management
- JSON Web Tokens (JWT)
- Org Authorization Server
- Custom Authorization Server
- Default Custom Authorization Server
Solution
What are the token lifetimes for the Org Authorization Server?
Administrators cannot modify the hard-coded token lifetimes when using the built-in Org Authorization Server. Review the following hard-coded token lifetime limits that the built-in Org Authorization Server enforces.
- ID Token: 60 minutes.
- Access Token: 60 minutes.
- Refresh Token: 90 days.
Custom Authorization Servers Provide Configurable Token Lifetimes
When using a Custom Authorization Server or the Default Custom Authorization Server, administrators configure token lifetimes within specific ranges. Review the following configurable token lifetime ranges and configuration methods that Custom Authorization Servers provide.
| Token Type | Minimum Lifetime | Maximum Lifetime | Configuration Method |
|---|---|---|---|
| ID Token | 5 minutes | 24 hours | Token Inline Hook |
| Access Token | 5 minutes | 24 hours | Access Policies or Token Inline Hook |
| Refresh Token | 10 minutes | Unlimited | Access Policies |
