# Offline token and active session max

**URL:** <https://forum.keycloak.org/t/offline-token-and-active-session-max/2993>\
**Category:** Getting advice\
**Tags:** adapter-javascript, authentication\
**Created:** [May 27, 2020, 3:27pm UTC](https://forum.keycloak.org/t/offline-token-and-active-session-max/2993 "2020-05-27T15:27:54Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![BrunoFL](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/brunofl/32/890_2.png) [@BrunoFL](https://forum.keycloak.org/u/BrunoFL)\
**Post date:** [May 27, 2020, 3:27pm UTC](https://forum.keycloak.org/t/offline-token-and-active-session-max/2993/1 "2020-05-27T15:27:54Z")

</div>

Hi,

I want to make an app logged with an offline token.

```
const config = {
    clientId: "CLIENT", promiseType: "native"
    realm: "dev", scope: "offline_access",
    url: "https://XXX/auth",
    refreshToken: this.getOfflineToken()
}
this.keycloak.init(config).then((authenticated) => {
    if (!authenticated) {
        this.keycloak.login(config)
    }
}).catch((a) => {
    console.error(a)
})

this.keycloak.onAuthSuccess = () => {
    this.setStorageOfflineToken()
}

```

1. At first login, config.refreshToken is not set, so authenticated = false
2. I do login()
3. Go back in my app, and authenticated = true !
4. At each refresh tokens, offline token is set in localstorage
5. At second login, config.refreshToken is an offline refresh token, so authenticated = true !

**And, when the active session is finished, I’m disconnected**

I test with a short **SSO Session Max** (2 mins) and I need to re-log with login/password after this 2 mins.  
In the admin tab, the offline session is still active.

It looks like this issue [https://issues.redhat.com/browse/KEYCLOAK-4201](https://issues.redhat.com/browse/KEYCLOAK-4201)  
And in documentation "an offline token will never expire by default and is not subject of the `SSO Session Idle timeout` and `SSO Session Max lifespan`" [https://www.keycloak.org/docs/latest/server\_admin/index.html#\_offline-access](https://www.keycloak.org/docs/latest/server_admin/index.html#_offline-access)

We can’t have unlimited active session ?  
It’s a bug ? Or I misunderstood something?

Thank you for your help.

---

<div class="post-metadata">

**Author:** ![BrunoFL](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/brunofl/32/890_2.png) [@BrunoFL](https://forum.keycloak.org/u/BrunoFL)\
**Post date:** [May 28, 2020, 8:32am UTC](https://forum.keycloak.org/t/offline-token-and-active-session-max/2993/2 "2020-05-28T08:32:52Z")

</div>

I try with curl :

```auto
KC_REALM=dev
KC_CLIENT=client
USERNAME=plok
PASSWORD=plok

refresh_token=`curl -k \
-d "client_id=$KC_CLIENT" \
-d "username=$USERNAME" \
-d "password=$PASSWORD" \
-d "grant_type=password" \
-d "scope=openid info offline_access" \
https://localhost:8080/auth/realms/$KC_REALM/protocol/openid-connect/token | jq -r '.refresh_token'` 

echo $refresh_token

while (true)
do
echo '\n\n\n'
curl -k \
 -d "client_id=$KC_CLIENT" \
 -d "grant_type=refresh_token" https://localhost:8080/auth/realms/$KC_REALM/protocol/openid-connect/token \
 -d "refresh_token=$refresh_token" | jq
echo `date`
sleep 10s
done

```

And I don’t have this problem, the active session is not deleted.

---

<div class="post-metadata">

**Author:** ![BrunoFL](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/brunofl/32/890_2.png) [@BrunoFL](https://forum.keycloak.org/u/BrunoFL)\
**Post date:** [June 2, 2020, 7:18am UTC](https://forum.keycloak.org/t/offline-token-and-active-session-max/2993/3 "2020-06-02T07:18:58Z")

</div>

Jira issue [https://issues.redhat.com/projects/KEYCLOAK/issues/KEYCLOAK-14319](https://issues.redhat.com/projects/KEYCLOAK/issues/KEYCLOAK-14319)

And it’s officially a bug.
