ContentsThe library

Proving Who You Are

Two Tokens Beat One

Last timeTokens That Carry Their Own Claim

One token cannot be both short-lived and convenient. Splitting the job in two, a short worker and a long renewer, resolves the conflict and makes theft detectable.

One token, two goals

The previous lesson ended with a dilemma. The staleness window of a

self-contained token is exactly its lifetime, so you want the lifetime

short. But when it expires the holder has to prove who they are again, and

proving who you are means a password and probably a second factor, so you

want the lifetime long.

Pick one number and both goals are compromised. A five-minute token means

signing in roughly a hundred times a working day, which nobody will accept.

A one-week token means a week of stale permissions, which nobody should

accept. The usual choice, an hour or a day, is a number that is bad at both

jobs rather than good at either, arrived at by splitting the difference

between two incompatible requirements.

The resolution is not a better number. It is noticing that the two goals

belong to two different activities and giving each its own token.

FIG 1The compromise, and the way out
staleness window is smalthe person signs in rareworks for a browser leftwithdrawal lands in minu
one token, five minutes1001
one token, one week0110
one token, one hour1100
two tokens, five minutes1111
Only the last row has every column. The third row is the common choice and it is the only one that fails on both of the first two columns at once, which is what splitting a difference between incompatible goals usually produces.

Splitting the job

Two tokens, with two jobs.

The access token is short, typically five to fifteen minutes. It is the one

sent with ordinary requests to ordinary services, and it is the natural

place for a self-contained signed statement, because its staleness window

is small enough to accept.

The refresh token is long, typically days or weeks. It is sent to exactly

one place, the authority that issues tokens, and it does exactly one thing:

it asks for a new access token. It is never sent to a business service, it

never authorises a read or a write, and it is always a handle checked

against a store rather than a self-contained statement.

The short lifetime now costs an exchange with the authority rather than a

sign-in by the person. The person notices nothing.

FIG 2How often the exchange happens
exchanges needed over one period of use
how long the person stays signed in
lifetime of the access token
An eight-hour working day against a five-minute access token is ninety-six exchanges, every one of them invisible to the person and none of them requiring a password. The same eight hours with a single five-minute token would be ninety-six sign-ins.
FIG 3What a shorter access token costs the authority
0.00100.00200.00300.00400.005.018.832.546.360.0access token lifetime, minutes
exchanges per user per day
The curve is steep at the left, which is the real constraint on how short the access token can be. Going from fifteen minutes to five triples the load on the one service that cannot be allowed to fall over, since when it is down nobody can renew anything.

That last point deserves emphasis. The authority becomes a hard dependency

for the whole system, on a schedule set by the access token lifetime. It

needs to be the most available thing you run, and the arithmetic above is

how you size it.

The lesson stops here

4 more paragraphs to go

You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.

The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.

See the planThe contents

This is the reading half

Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.

The contents

The rest of this course

  1. 01Who You Are, What You May Do, and Who Remembers
  2. 02What Each Kind of Proof Actually Resistsopening only
  3. 03The Thing the Browser Carriesopening only
  4. 04The Token That Answers for Itselfopening only
  5. 05Two Tokens Beat Oneyou are here
  6. 06Borrowing Somebody Elses Proofopening only
  7. 07The Request Your Browser Sent for Somebody Elseopening only
  8. 08Making Somebody Stop Being Signed Inopening only

Read alongside