Certain APIs will no longer count towards user activity for the purposes of idle token expiration

Description

When an organization has idle token expiration configured, access tokens are revoked if they are not used for a specified period of time. API requests reset that period. This change makes specific APIs not reset that period. The APIs still require authentication.

Change Category

API

Change Context

Automation by some clients was inadvertently preventing tokens from being expired due to inactivity.

Change Impact

Clients may notice tokens becoming invalid more frequently due to inactivity.
Users may experience more prompts to authenticate, in accordance with their organizations idle token policy.

Date of Change

April 5, 2023

Impacted APIs

api/v2/featuretoggles
api/v2/diagnostics/newrelic/insights
api/v2/diagnostics/trace
api/v2/integrations/clientapps
api/v2/users/me

References

[https://inindca.atlassian.net/browse/IAM-1988|https://inindca.atlassian.net/browse/IAM-1988]

This topic was automatically closed 62 days after the last reply. New replies are no longer allowed.