Forums

Articles
Create
cancel
Showing results for 
Search instead for 
Did you mean: 

Can we update the expiration of refresh token in 3LO OAuth2.0 apps ?

Madhura Lodam September 27, 2023

I have created an app in developer console where I have added authorization 3LO OAUTH2.0 , in the authorization url added offline_access in the scope. 

On the official documentation  https://developer.atlassian.com/cloud/confluence/oauth-2-3lo-apps/  the refresh token expiration details are mentioned.

90 days - Inactivity expiration

365 days - absolute expiration

 


On the same doc we have OAuth0 by okta documentation where we can disable the expiration of refresh token, Is there a way in atlassian OAuth2.0 apps where we can disable the expiration of refresh token? 

 

Thanks!

 

1 answer

0 votes
ELFAPP Technologies
Rising Star
Rising Star
Rising Stars are recognized for providing high-quality answers to other users. Rising Stars receive a certificate of achievement and are on the path to becoming Community Leaders.
September 27, 2023

Hi,

The refresh token from Atlassian is a rotating one and not persistent. However, there's no configuration within the developer console that disables the refresh token. I believe the docs mention using the dashboard from auth0 directly. Although, I'm not certain how that works. Typically, I would say that as long as the user remains active within a 1 year period the refresh token won't be invalidated.

Suggest an answer

Log in or Sign up to answer
DEPLOYMENT TYPE
CLOUD
PRODUCT PLAN
PREMIUM
TAGS
AUG Leaders

Atlassian Community Events