DEV Community

Discussion on: Is there a official recommendation for the access token and refresh token life time?

Collapse
 
byrro profile image
Renato Byrro

What do you mean by "official recommendation"? I'm not aware of any "Token Authority Foundation" setting industry standards... You should consider security, convenience, or any other factors particular to your case.

Is it an internet banking system? I'd set the token to expire in short minutes.

Is it like Facebook that wants to track and know who you are when you visit a page with a "like" widget? Probably would set to expire in months.

Collapse
 
ahmedam55 profile image
Ahmed Mahmoud

That's really helpful. Thank you so much for your time and effort 😊