Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

  • Refresh token expires (after 90 days)
  • User closes browser tab (sessionStorage cleared)
  • User clicks "Logout"
  • Admin revokes user's access in Azure AD

...

Token Details

Access Token (JWT)

Purpose: Proves user is authenticated and authorized for API calls Lifetime: 1 hour Contains:

  • User ID
  • User email
  • Azure AD groups (for authorization)
  • Expiration time
  • Issuer (Microsoft Entra ID)
  • Audience (ApiService)

Example (decoded):

{
  "iss": "https://6073ce8b-73f3-4df4-9b80-5e40cdc6965f.ciamlogin.com/.../v2.0",
  "aud": "api://4dad5d62-dc8c-4378-8bd0-ae736a4d73fe",
  "sub": "abc123...",
  "name": "John Doe",
  "email": "john.doe@contractor.com",
  "groups": ["ac6ec653-2ae3-457a-9302-d42429d83bee"],
  "exp": 1733754123
}

Refresh Token

Purpose: Get new access tokens without re-login Lifetime: 90 days Contains: Encrypted data (not readable) Note: Single-use (new refresh token issued with each renewal)

ID Token (JWT)

Purpose: User identity information for the frontend Lifetime: 1 hour Contains: Similar to access token but for frontend use Note: Not used for API authorization


...

Microsoft Graph API (Separate from Main Flow)

...