OIDC tokens and refresh
Lifetimes
Section titled “Lifetimes”| Token | Lifetime |
|---|---|
| Access token | 1 hour |
| ID token | 1 hour |
| Refresh token | 7 days, renewed at each refresh |
| Grant (the sign-in itself) | Expires after 30 days without use, extended on each use |
| Browser session on the provider | 30 days |
| Sign-in page (login and consent) | 1 hour |
As long as your application refreshes at least once every 7 days, the member stays signed in without a new login.
Getting a refresh token
Section titled “Getting a refresh token”All three conditions are needed:
- your client has the
refresh_tokengrant; offline_accessis in the requestedscope;- the authorization request carries
prompt=consent.
Refresh token rotation
Section titled “Refresh token rotation”Refresh tokens are always rotated: each refresh returns a new refresh_token and invalidates the one you sent.
POST /tokenAuthorization: Basic base64(client_id:client_secret)Content-Type: application/x-www-form-urlencoded
grant_type=refresh_token&refresh_token=<current refresh token>The response holds access_token, token_type: "Bearer", expires_in, scope, id_token and the new refresh_token. Store the new refresh token — replacing the old one atomically — before you use the new access token.
Reuse detection
Section titled “Reuse detection”- Serialise refreshes per member: a lock, or a single in-flight refresh promise shared by every caller.
- Never retry a refresh with the old token after a timeout: the first attempt may have succeeded.
- After
invalid_grant, send the member through the sign-in again.
When tokens stop working
Section titled “When tokens stop working”Besides expiry, a sign-in is revoked when:
- the member changes or resets their password, or changes their username;
- the member’s account is deactivated;
- the office disconnects your application from Settings › Connectors;
- Ubikap disables your client;
- the member leaves their office:
/meanswers401 invalid_tokenand a refresh answers400 invalid_scopefor theofficescope.
In every case, start a new sign-in.
Revoking and introspecting
Section titled “Revoking and introspecting”Both endpoints authenticate with your client credentials, and only accept tokens issued to your own client.
POST /token/revocationwithtoken(and optionallytoken_type_hint=refresh_token): revoke a token, e.g. when the member signs out of your application.POST /token/introspectionwithtoken: returnsactiveand, for an active token, itsscope,client_id,subandexp.
See OIDC provider for endpoints and scopes.