<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Refresh Token Idle Lifetime Explanation

API Access Management
Okta Classic Engine
Okta Identity Engine

Overview

Administrators configure the lifetime of access tokens and refresh tokens on a custom authorization server to a specific value or set them to unlimited. The idle refresh token lifetime setting forces tokens to expire after a designated period of inactivity. The expiration window must fall between the access token lifetime and the refresh token lifetime, with a maximum limit of 1825 days.

Applies To

Solution

How does the idle refresh token lifetime setting function?

Administrators can set the lifetime of the access token and refresh token to a custom value or to no lifetime on a custom authorization server.

access token lifetime

Additionally, administrators configure a setting that forces tokens to expire after a specific period of inactivity. Okta enforces specific rules for the idle refresh token lifetime.

refresh token idle time

The expiration window must fall between the access token lifetime and the refresh token lifetime. The expiration window cannot exceed a maximum limit of 1825 days. If administrators set the idle lifetime to 30 minutes, Okta expires the refresh token if it remains unused for that duration.

 

Related References

Loading
Okta Support - Okta Refresh Token Idle Lifetime Explanation