
qe3uw (qe3uw) asked a question.
Is there some way to configure Okta token timeout due to the user's inactivity? As far as I can see in the documentation, there is no mention of such settings.
For example: if the user is active, then the lifetime of the token is 12 hours, and if the user is inactive, then the lifetime of the token should be 2 hours.

Hello @qe3uw (qe3uw),
Thank you for posting.
You can increase the session lifetime by going to Security -> Authentication -> Sign On -> Add New Okta Sign-on Policy on top of the default one. There you can select the groups that will be affected by the change, after which you will be prompted to add a rule. There you will find Session Lifetime at the bottom with the default setting of 2 hours, you can change it to up to a maximum of 90 days.
Also, the token lifetime can be modified from Security > API > Authorization Servers > Access Policies > Add and configure a new rule or modify the default. The ID Tokens are not listed as they can't be modified from the 60 minutes default lifetime.
I hope this helps,
Natalia
Okta Inc.