<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009w5oWbCAIOkta Classic EngineAPI Access ManagementAnswered2025-02-04T09:00:53.000Z2024-01-04T08:14:36.000Z2024-01-08T23:09:53.000Z

vagu1 (vagu1) asked a question.

Default authorization server, access token and refresh token lifetime

I'm using default authorization server. I've also added access policies and rules that define access token lifetime (let's say 2 hours). I've also assigned the policy to the client application. But when I login, my access token shows 1 hour expiry and refresh token shows 3 months expiry. I've also changed default policy rule for access token and refresh token lifetime but no change in result. What am I missing here?


This question is closed.
Loading
Default authorization server, access token and refresh token lifetime