Skip to content

[changelog] [Announcement] Forge corrected TTL for offline user impersonation tokens #33

Description

@nyxthedev

GUID: CHANGE-3426
pubDate: Fri, 04 Sep 2026 16:50:56 GMT
Category: Announcement

What's changing

Atlassian fixed a bug where the ttl returned for Forge Remote offline user impersonation tokens (the offlineUserAuthToken mutation) could incorrectly report 30 minutes even though the token stayed valid for up to four hours. The returned ttl now accurately reflects the token's remaining validity. Actual token lifetime is unchanged; only the reported value was wrong. Apps that hard-coded a 30-minute refresh workaround are advised to switch to trusting the returned ttl, caching tokens longer and refreshing less often.

Parity impact for forge-sim

Area: remotes / external auth (Forge Remote token simulation). If forge-sim simulates the offlineUserAuthToken mutation or any offline user impersonation token issuance for remotes, the simulated ttl should reflect the real remaining validity (up to ~4h), not a fixed 30 minutes. Apps updated per this changelog (trusting ttl for refresh scheduling) should see the same refresh cadence in forge-sim as in Forge. If forge-sim doesn't model offline impersonation tokens yet, this pins the correct semantics to use when it does.

Link: https://developer.atlassian.com/platform/forge/changelog/#CHANGE-3426

  • forge-spec: update affected requirement rows (behavior change)

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions