Token Generated Using SAML 2.0 Assertion Grant Has Unexpected Lifetime in Okta
Last Updated:
Overview
When using the SAML Assertion Grant type, the SAML assertion that is exchanged for tokens affects the lifetime of the Refresh Token issued by this flow. If the SAML assertion's lifetime is shorter than the configured Refresh Token lifetime for the Authorization Server used, the lifetime for refresh tokens issued using the SAML 2.0 Assertion flow will be set to the lifetime for the SAML assertion.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic
- OpenID Connect (OIDC)/OAuth application
- SAML 2.0 Assertion Grant Type
- Refresh Tokens
Solution
When does the SAML Assertion's lifetime control the Refresh Token's lifetime?
When using the SAML Assertion Grant type, the SAML assertion that is exchanged for tokens affects the lifetime of the Refresh Token issued by this flow. If the SAML assertion's lifetime is shorter than the configured Refresh Token lifetime for the Authorization Server used, the lifetime for refresh tokens issued using the SAML 2.0 Assertion flow will be set to the lifetime for the SAML assertion.
When does the Authorization Server's configuration control the Refresh Token's lifetime?
If the SAML assertion's lifetime is instead longer than the configured Refresh Token lifetime for the Authorization Server used, the Refresh Token will receive the lifetime for that Authorization Server.
Note that per Lifetime of the Okta Minted JSON Web Tokens (JWT), the lifetime of Refresh Token's issued by the Org Authorization Server is 90 days, while the lifetime of Refresh Token's issued by a Custom Authorization Server is based on the configuration of the Access Rule evaluated when the token is granted.
