<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z0000AIcvp5CQBOkta Classic EngineAuthenticationAnswered2026-01-27T09:00:21.000Z2024-12-25T07:55:43.000Z2024-12-31T17:10:09.000Z

xiwrq (xiwrq) asked a question.

Does public key created in OIDC app expire? if yes, where can i check date of expiry in okta portal?

Does public key created in OIDC app expire? if yes, where can i check date of expiry in okta portal?

Image is not available


  • Mihai N. (Okta, Inc.)

    @xiwrq (xiwrq)​ I ran this by my colleagues and confirmed that the keys the authorization server uses to sign tokens are rotated by Okta, but keysets that an admin configures for an OIDC app are not expired by Okta. These keys are under the control of the admin whether to choose to periodically delete and recreate or not.

     

    Regards.

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
  • Mihai N. (Okta, Inc.)

    Hi @xiwrq (xiwrq)​ , Thank you for reaching out to the Okta Community! 

     

    As far as I can see the public keys do not expire. 

    That being said, there are a few situations in which the keys are deleted. Please check this documentation for the details. 

     

     

     

    If my answer helped, remember to mark it as best to increase its visibility for other members of the Okta Community who might have the same questions as you. 

     

    Hope my answer helps! 

     

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
  • xiwrq (xiwrq)

    Hi @Mihai N. (Okta, Inc.)​ 

    Thanks for the response, yeah i too do not see anything specified regarding expiry in the article. So can i consider that okta neither revokes public keys nor sets an expiry date to public keys.

    Sorry if i am asking the same question, but i need this information in a important business discussion. can you please help doing fact check with relevant okta product team and provide a confirmation?

    Thank you very much!

    Expand Post
    • Mihai N. (Okta, Inc.)

      @xiwrq (xiwrq)​ I ran this by my colleagues and confirmed that the keys the authorization server uses to sign tokens are rotated by Okta, but keysets that an admin configures for an OIDC app are not expired by Okta. These keys are under the control of the admin whether to choose to periodically delete and recreate or not.

       

      Regards.

      --

      Help others in the community by liking or hitting Select as Best if this response helped you.

      Expand Post
      Selected as Best
This question is closed.
Loading
Does public key created in OIDC app expire? if yes, where can i check date of expiry in okta portal?