Token lifetimes instead of revocation

There is no distributed revocation — expiry does that job. Current profile (v1.3): access/ID tokens 1 hour (15 min–6 h), refresh tokens 30 days (1–400 days, revocable server-side in the IAM database), issuer key cache refresh 6 h, cache expiration 2 days, issuer keys 6 months. The original v1.0 (2019) said 20 minutes / 10 days — values still widely quoted, several revisions out of date: the profile itself notes the old limits proved too costly for critical workflows.


Topology