OAuth doesn’t specify and specific timeout period, it’s up to the AS that issues the token to determine how long the token is good for. RFC7009 isn’t about timeout periods, it’s about the client proactively telling the AS that it doesn’t need a token anymore and the AS should throw it out, likely prior to any timeouts.
— Justin > On May 25, 2017, at 12:23 PM, Brig Lamoreaux <[email protected]> > wrote: > > Hi, > > What is the specified timeout period to invalidate the token? > > Brig Lamoreaux > Data Solution Architect > [email protected] <mailto:[email protected]> > 480-828-8707 > US Desert/Mountain Tempe > > > <image001.jpg> > > > > _______________________________________________ > OAuth mailing list > [email protected] <mailto:[email protected]> > https://www.ietf.org/mailman/listinfo/oauth > <https://www.ietf.org/mailman/listinfo/oauth>
_______________________________________________ OAuth mailing list [email protected] https://www.ietf.org/mailman/listinfo/oauth
