Skip to main content

Token Management

CloudBase Authentication implements user session management based on a dual-token mechanism using Refresh Token and Access Token. You can flexibly configure token expiration policies and session concurrency limits to achieve the best balance between security and user experience.

Configuration Parameters

ParameterDefaultConfigurable RangeDescription
Refresh Token Validity Period30 days1 hour - 30 daysAfter expiration, cannot obtain new Access Token, requires re-login
Access Token Validity Period2 hours1 - 24 hoursAfter expiration, use Refresh Token to obtain new token, no re-login required.
Maximum Sessions11 - 100When the number of sessions exceeds the set threshold, the system will automatically invalidate the oldest Refresh Token to effectively prevent account abuse.

Configuration Operations

Go to CloudBase Console/Identity Authentication/Token Management to adjust your token strategy.

💡 Tip: Configuration changes take effect immediately, but do not affect already issued tokens; they only apply to newly logged-in users.

Best Practice Recommendations

  • Management Applications: It is recommended to set the Access Token validity period to 1 hour and the maximum number of sessions to 1 to reduce the risk of token leakage.

  • Content/Social Applications: It is recommended to extend the Refresh Token to 30 days to provide a seamless long-term login experience.