// SESSION TOKEN // ACCESS CONTROL
⬡
// VERIFICATION FACTOR 7 OF 7

🛡 Session Token

A cryptographically signed JWT issued by Keycloak after successful YubiKey authentication. The token has a 45-minute TTL and is validated on every API call. An expired or missing token blocks access regardless of other factors.

✓
VALID
JWT valid · Expires in 43 min · Issued by secure-os realm
SESSION COUNTDOWN
43:00
Time remaining in current session
✓ Session active · JWT signed by Keycloak secure-os realm · YubiKey FIDO2 verified
TOKEN POLICY
⏱
45 MIN TTL
Tokens expire 45 minutes after issue. After expiry, YubiKey touch is required to get a new token. This limits the window of exposure if a token is somehow intercepted.
🔐
RS256 SIGNED
Keycloak signs tokens with RSA-256. The SNO backend fetches the JWKS public key from Keycloak and validates the signature on every API call.
🚫
NO REFRESH
Refresh tokens are disabled in SNO. Every new session requires a fresh YubiKey authentication. There is no "remember me" or persistent login.
☠
KILL SWITCH
The kill switch immediately marks all tokens as revoked in the SNO database. Even a valid, unexpired JWT will be rejected after a kill switch activation.
KEYCLOAK SESSION SETTINGS
1

Open Realm Settings

Keycloak Admin → secure-os realm → Sessions tab. Set SSO Session Max to 45 minutes and SSO Session Idle to 30 minutes.

2

Disable Refresh Tokens

In the sno-dashboard client settings → Advanced → disable Use Refresh Tokens. Users must re-authenticate with YubiKey after each 45-minute session.

3

Enable Brute Force Protection

Realm Settings → Security Defenses → enable Brute Force Detection. Set permanent lockout after 5 failures. This blocks credential stuffing even with YubiKey required.

SETUP LINKS