Contract
Session and logout
Your app's session is derived from the IdP's. Lifetimes, refresh on expiry, 401 on refusal, fail closed, blocking within 5 minutes, and logout of both sessions.
The local session is derived from the IdP’s. When the access token expires, refresh at the IdP; a refused refresh ends the local session.
Lifetimes
Section titled “Lifetimes”Declared in the IdP’s realm.json and reapplied on every deploy; an engine upgrade does not change them.
| Element | Value | Role |
|---|---|---|
accessTokenLifespan | 300 s (5 min) | revocation limit |
ssoSessionIdleTimeout | 1800 s (30 min) | without activity, the central session ends |
ssoSessionMaxLifespan | 36000 s (10 h) | absolute ceiling of the central session |
| your app’s local session | at most ssoSessionMaxLifespan | never outlives the central session |
Storage and revalidation
Section titled “Storage and revalidation”Store tokens on the server, as credentials. The refresh_token, the id_token and the access token’s expiry, bound to the session record. In the BFF shape the browser gets only the session id, in an HttpOnly cookie.
On expiry, refresh. Exchange the refresh token for a new one. Success: continue. Refused: destroy the local session and answer 401. No call to the IdP on every request; no grace period after expiry.
IdP unreachable: fail closed. The refresh fails, the local session ends, and the person signs in again when the IdP is back. “Blocked” and “unreachable” are indistinguishable to your app.
No offline_access. No managed client gets a long-lived refresh token; every refresh goes through the central session. A block takes effect within 5 min, with no revocation bus, queue or worker.
Blocking
Section titled “Blocking”Blocking a person at the IdP is disabling the account and ending all of its sessions (disabling alone does not end a live session). The IdP then refuses every refresh; residual access ends within 5 min, the lifetime of the access token already issued.
| Moment | What happens |
|---|---|
| t | the IdP administration disables the account and ends its sessions |
| t to t + 5 min | the access token already issued is valid until its exp |
at exp | your app tries the refresh; the IdP answers invalid_grant |
| right after | your app destroys the local session and answers 401 |
To remove someone from your app only, change their permissions in your app: Identity and access.
Logout
Section titled “Logout”Signing out is ending the local session and redirecting to end_session_endpoint with id_token_hint. That ends the current central session: the next app the person opens asks for the password. Sessions on other devices stay.
Do both parts: the local one and the central one (post_logout_redirect_uri must be in the descriptor’s postLogoutRedirectUris).
Ending all of one’s own sessions: the person, in the account console (device activity) at https://id.institutourupema.com.br/realms/urupema/account, or the IdP administration.
Restart
Section titled “Restart”Single instance, no high availability, no SLA. A restart signs everyone out of every app within 5 min. The rules above cover it; nothing else is required.