<div dir="ltr">You're talking about access and refresh tokens, and not OIDC session management, right?<div><br></div><div>Refresh tokens are sent to the token endpoint to obtain a new access token.</div><div><br></div><div>For "validate", are you interested in the Introspection endpoint? Not being terribly knowledgeable about the operations of the extension, it looks to me like it probably needs to be added to the OP metadata template:<br><a href="https://github.com/CSCfi/shibboleth-idp-oidc-extension/blob/1cb253121d82ced9ce6c283fbd1f9ce88e46e64e/roles/oidc-extension/templates/openid-configuration">https://github.com/CSCfi/shibboleth-idp-oidc-extension/blob/1cb253121d82ced9ce6c283fbd1f9ce88e46e64e/roles/oidc-extension/templates/openid-configuration</a><br></div><div><br></div><div>Greg</div><div><br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Aug 27, 2019 at 8:50 AM Wessel, Keith <<a href="mailto:kwessel@illinois.edu">kwessel@illinois.edu</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">All,<br>
<br>
The same developers who were talking to me yesterday about access token and refresh token lifetimes pointed out to me that the refresh and validate endpoints aren't listed in our opened-configuration. I checked the template that ships with the extension and, sure enough, they aren't there. Is there a reason for this? If not, can someone help me figure out what those URLs should be so I can add them?<br>
<br>
Thanks,<br>
Keith<br>
<br>
-- <br>
For Consortium Member technical support, see <a href="https://wiki.shibboleth.net/confluence/x/coFAAg" rel="noreferrer" target="_blank">https://wiki.shibboleth.net/confluence/x/coFAAg</a><br>
To unsubscribe from this list send an email to <a href="mailto:users-unsubscribe@shibboleth.net" target="_blank">users-unsubscribe@shibboleth.net</a><br>
</blockquote></div>