Skip to end of metadata
Go to start of metadata

You are viewing an old version of this page. View the current version.

Compare with Current View Page History

Version 1 Current »

In theory there is no limit for expiration time of JWT. Everything depends on context where we use JWT. For trivial cases (most web pages), token may expire after 1 month.

Because of "The Scheduler" sensitive data (critical business data), the expiration time can not be too long. The best practice is set expiration duration for 15 minutes - as it's set in The Scheduler.

The point is that 15 minutes is best choice to keep the users more safe (JWT is validated for short time, even if has been stolen).

In the future, we are planning to improve refresh mechanism.

  • No labels