<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Lifetime of the Okta Minted JSON Web Tokens (JWT)

Okta Classic Engine
All Engines
Okta Identity Engine
API Access Management

Overview

The default and configurable lifetimes of Okta-minted JSON Web Tokens (JWT) vary depending on the authorization server type. The built-in Org Authorization Server uses hard-coded token lifetimes, while Custom Authorization Servers allow configurable token lifetimes within specific ranges.

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • OpenID Connect / OAuth 2.0 applications
  • API Access Management
  • JSON Web Tokens (JWT)
  • Org Authorization Server
  • Custom Authorization Server
  • Default Custom Authorization Server

Solution

What are the token lifetimes for the Org Authorization Server?

Administrators cannot modify the hard-coded token lifetimes when using the built-in Org Authorization Server. Review the following hard-coded token lifetime limits that the built-in Org Authorization Server enforces.

  • ID Token: 60 minutes.
  • Access Token: 60 minutes.
  • Refresh Token: 90 days.

 

Custom Authorization Servers Provide Configurable Token Lifetimes

When using a Custom Authorization Server or the Default Custom Authorization Server, administrators configure token lifetimes within specific ranges. Review the following configurable token lifetime ranges and configuration methods that Custom Authorization Servers provide.

Token TypeMinimum LifetimeMaximum LifetimeConfiguration Method
ID Token5 minutes24 hoursToken Inline Hook
Access Token5 minutes24 hoursAccess Policies or Token Inline Hook
Refresh Token10 minutesUnlimitedAccess Policies

 

Related References

Loading
Lifetime of the Okta Minted JSON Web Tokens (JWT) | Okta Support