GUID: CHANGE-3426
pubDate: Fri, 04 Sep 2026 16:50:56 GMT
Category: Announcement
What's changing
Atlassian fixed a bug where the ttl returned for Forge Remote offline user impersonation tokens (the offlineUserAuthToken mutation) could incorrectly report 30 minutes even though the token stayed valid for up to four hours. The returned ttl now accurately reflects the token's remaining validity. Actual token lifetime is unchanged; only the reported value was wrong. Apps that hard-coded a 30-minute refresh workaround are advised to switch to trusting the returned ttl, caching tokens longer and refreshing less often.
Parity impact for forge-sim
Area: remotes / external auth (Forge Remote token simulation). If forge-sim simulates the offlineUserAuthToken mutation or any offline user impersonation token issuance for remotes, the simulated ttl should reflect the real remaining validity (up to ~4h), not a fixed 30 minutes. Apps updated per this changelog (trusting ttl for refresh scheduling) should see the same refresh cadence in forge-sim as in Forge. If forge-sim doesn't model offline impersonation tokens yet, this pins the correct semantics to use when it does.
Link: https://developer.atlassian.com/platform/forge/changelog/#CHANGE-3426
GUID: CHANGE-3426
pubDate: Fri, 04 Sep 2026 16:50:56 GMT
Category: Announcement
What's changing
Atlassian fixed a bug where the
ttlreturned for Forge Remote offline user impersonation tokens (theofflineUserAuthTokenmutation) could incorrectly report 30 minutes even though the token stayed valid for up to four hours. The returnedttlnow accurately reflects the token's remaining validity. Actual token lifetime is unchanged; only the reported value was wrong. Apps that hard-coded a 30-minute refresh workaround are advised to switch to trusting the returnedttl, caching tokens longer and refreshing less often.Parity impact for forge-sim
Area: remotes / external auth (Forge Remote token simulation). If forge-sim simulates the
offlineUserAuthTokenmutation or any offline user impersonation token issuance for remotes, the simulatedttlshould reflect the real remaining validity (up to ~4h), not a fixed 30 minutes. Apps updated per this changelog (trustingttlfor refresh scheduling) should see the same refresh cadence in forge-sim as in Forge. If forge-sim doesn't model offline impersonation tokens yet, this pins the correct semantics to use when it does.Link: https://developer.atlassian.com/platform/forge/changelog/#CHANGE-3426