
MichaelH.97932 (Primerica) asked a question.
Does OAG check the session timeouts locally or does it make a call to the ORG?
After authentication is complete for a header based application are the session timeouts evaluated locally in the appliance or is there a call to the ORG every time a protected resource is requested?

Hi @MichaelH.97932 (Primerica) , Thank you for reaching out to the Okta Community!
I ran this question by my OAG colleagues to confirm.
Session timeouts are evaluated on OAG node. After expiration the request to protected resource will get redirected based on https://help.okta.com/oag/en-us/content/topics/access-gateway/task-define-application-behaviors.htm#No_Session/Session_Expired
If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you.
Hope my answer helps!
--------------------------------
Headed to Oktane? Here's what you can expect, plus all the Okta tips you may have missed this month