May 28, 2026 · Jogajog team · 2 min read
Quick answer: Access tokens live fifteen minutes; sessions renew silently through rotating refresh tokens for up to thirty days of use. Stolen tokens age out fast, refresh reuse is detected, and members experience none of it — just an app that stays signed in.
Rotation means a copied refresh token betrays itself on second use.
Suspension and removal cut new tokens immediately; short access life bounds the tail.
Sign-out on shared devices revokes the session server-side.
Long enough that phones feel permanently signed in, short enough that lost devices age out.
Trashing or suspending the member does exactly that.
Free branded demo, built from your spreadsheet, this week.
Get your free demo