TrustPortDocs

The two tokens

Access tokenRefresh token
What it is forSent with every request to prove who the user isExchanged for a new access token when the old one expires
Lifetime15 minutes30 days
FormatSigned JWT your servers can verifyOpaque random string
Where to keep itMemory, or a secure cookieServer side, or an HttpOnly cookie. Never in local storage
Can be reusedYes, until it expiresNo. Each refresh returns a new one and retires the old one

What's inside an access token

substring
The user’s ID.
tidstring
Your workspace ID.
sidstring
The session ID. Every token from the same sign-in shares it.
rolesstring[]
The user’s roles, including custom roles you created.
expnumber
When the token expires, in seconds since 1970.
custom claimsany
Anything your post-login actions added.

Verify a token on your server

Access tokens are signed with RS256. Fetch the public keys from your JWKS endpoint, cache them, and check the signature and exp on every request. Most JWT libraries do this for you.

Public keys
GET https://id.trustportidentity.com/.well-known/jwks.json

Keep someone signed in

When an access token expires, swap the refresh token for a fresh pair:

Refresh
curl -X POST https://id.trustportidentity.com/api/v1/auth/refresh \
  -H "Content-Type: application/json" \
  -d '{ "refresh_token": "9f2c…" }'

Each refresh checks the account again. If the user has been deactivated or deleted in the meantime, the refresh fails and they must sign in again. Role changes show up in the next access token.

Sign people out

You want to…Do this
Sign the current user out of this devicePOST /api/v1/auth/logout with their access token
Sign yourself out everywhereAccount & Security › Sessions › Sign out everywhere, or POST /api/v1/auth/sessions/revoke-all
Sign someone else out everywhere and keep them outUsers › Lock account. Their sessions end straight away
Automatic sign-outs
Resetting or changing a password signs the user out of all their sessions. Their tokens stop working at once, not when they would have expired.

Your own sessions

In the dashboardAccount & Security›Sessions

If you think someone else has used your account, choose Sign out everywhere, change your password and check your two-factor devices.

© TrustPort IdentitySomething unclear? Tell us and we'll fix the page.