> For the complete documentation index, see [llms.txt](https://olddocs.exivity.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://olddocs.exivity.io/security/authentication/token.md).

# Token

## Authentication tokens

API tokens use the widely used JWT encoding format, and we take extra measures to harden the tokens:

* Configurable lifetime (defaults to 4 hours)
* Configurable storage policy (defaults to session storage)
* Revoked at logout
* Invalidate all user tokens on request
* Client fingerprinting

## Change the lifetime of a token<br>

By changing the lifetime of a token, users will be logged out after their token expires.\
\
Follow these instructions to change the lifetime of the token:<br>

1. Navigate to the [Settings](/administration/settings.md) page under the **Administrations** > **Settings** menu.
2. Select the **System** tab and scroll down to the *Security* section.
3. Choose the desired token lifetime from the dropdown menu:

![Token expiration times](https://1141395848-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FPRZvuYYNyI3vz1mar1l4%2Fuploads%2FW6ADsd4KWhQGQMbjFRQg%2Fimage.png?alt=media\&token=7d1c5f2c-9aa3-4854-8579-92e0b4f5431e)

4\. Click the **Update** button to apply the change.
