Table of Contents
When you update the “token duration” settings on an Authlete service that has already been issuing tokens, Authlete will:
This article explains how the “token duration” settings affect access tokens and refresh tokens.
The new duration settings are to be applied on (re)issuing access tokens on token requests with various grant types including refresh token grant.
The duration change may affect refresh tokens based on “Refresh Token Rotation ” settings.
To configure Refresh Tokens settings:
Navigate to Service Settings > Tokens and Claims > Refresh Tokens
Enable your desired Refresh Token Rotation options.
Click Save Changes
to apply the updates.
The Enable Token Rotation
Configuration item controls whether to keep a refresh token valid after its use or invalidate the used refresh token and issue a new one.
If “Enable Token Rotation
” is enabled
If “Enable Token Rotation
” is disabled
enabled
Refreshing a refresh token when the grant type is “refresh_token”