Skip to main content
Release Notes

Customize Token and Auth Session Expiry

Authress Tenant selection enables your users to be automatically redirected to their own corporate identity provider during authentication.

Authress optimizes for the User Experience. To do this, Authress attempts to keep your users logged even when the token expires. This is known as Silent Authentication By default, Authress generated JWTs expiry after 24 hours, and session expiry after 30 days. This may not be long enough or too long in some circumstances.

To handle compliance and regulatory requirements. Authress now enables changing the default token and auth session expiries to meet your customers' exact needs. With this release, the Authress Tenant token configuration, can be provided to change one or both of these lifetimes. This configuration is available either through the SDKs and the Authress API or through the Authress Management Portal in the SSO Tenant Provider configuration.

When configuring an SSO Tenant in the Authress Management Portal, navigate to the advanced tenant configuration, and specify values for the Token Configuration:

Tenant token configuration