# Keycloak token still is valid after logout (spring boot)

**URL:** <https://forum.keycloak.org/t/keycloak-token-still-is-valid-after-logout-spring-boot/11929>\
**Category:** Securing applications\
**Created:** [November 7, 2021, 12:04pm UTC](https://forum.keycloak.org/t/keycloak-token-still-is-valid-after-logout-spring-boot/11929 "2021-11-07T12:04:40Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![hosseinyzr](https://avatars.discourse-cdn.com/v4/letter/h/c37758/32.png) [@hosseinyzr](https://forum.keycloak.org/u/hosseinyzr)\
**Post date:** [November 7, 2021, 12:04pm UTC](https://forum.keycloak.org/t/keycloak-token-still-is-valid-after-logout-spring-boot/11929/1 "2021-11-07T12:04:40Z")

</div>

I’m using Keycloak and spring boot. the problem is when I log out session in Keycloak panel or with rest call in spring project, although the session will be removed from Keycloak, the user can still use that token to authenticate requests. as I found, it seems that the Keycloak adapter doesn’t check each token with the Keycloak server pwe request, is it true? how can I solve this?

as some topic answers said, I tried Backchannel Logout URL, but no success was achieved.  
this is error:o.k.a.s.a.KeycloakLogoutHandler.logout:62 - Cannot log out without authentication

---

<div class="post-metadata">

**Author:** ![xgp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/xgp/32/2589_2.png) [@xgp](https://forum.keycloak.org/u/xgp)\
**Post date:** [November 7, 2021, 7:35pm UTC](https://forum.keycloak.org/t/keycloak-token-still-is-valid-after-logout-spring-boot/11929/2 "2021-11-07T19:35:23Z")

</div>

Access tokens cannot be invalidated in Keycloak, only refresh tokens. That is why it is recommended to keep access token lifespan short (e.g. 1 minute), but refresh token lifespan long.

---

<div class="post-metadata">

**Author:** ![hosseinyzr](https://avatars.discourse-cdn.com/v4/letter/h/c37758/32.png) [@hosseinyzr](https://forum.keycloak.org/u/hosseinyzr)\
**Post date:** [November 13, 2021, 6:21am UTC](https://forum.keycloak.org/t/keycloak-token-still-is-valid-after-logout-spring-boot/11929/3 "2021-11-13T06:21:56Z")

</div>

Thanks, I’ll do this approach…  
But isn’t it dangerous? even with a 1-minute life span…  
and it has overhead on server because we should request many times to get a new access token with refresh token…  
Is there any plan to make this better in keycloak?

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [November 13, 2021, 8:19am UTC](https://forum.keycloak.org/t/keycloak-token-still-is-valid-after-logout-spring-boot/11929/4 "2021-11-13T08:19:25Z")

</div>

This is not related to Keycloak, this is OIDC spec.  
Please read the spec and understand the concepts.

---

<div class="post-metadata">

**Author:** ![hosseinyzr](https://avatars.discourse-cdn.com/v4/letter/h/c37758/32.png) [@hosseinyzr](https://forum.keycloak.org/u/hosseinyzr)\
**Post date:** [November 13, 2021, 8:33am UTC](https://forum.keycloak.org/t/keycloak-token-still-is-valid-after-logout-spring-boot/11929/5 "2021-11-13T08:33:02Z")

</div>

Thanks, I’ll do that. 🙏
