Access Token Does not Contain Expiration Time
Sep 10, 2025
Overview
Cause
Solution
Access tokens issued strictly for the purpose of accessing the OIDC
/userinfo endpoint have a default lifetime and can't be changed. The length of lifetime depends on the flow used to obtain the token:
| Flow | Lifetime |
|---|---|
| Implicit | 7200 seconds (2 hours) |
| Authorization Code/Hybrid | 86400 seconds (24 hours) |