How to refresh APNs Authentication Token?

Viewed 86

According to the APNs docs

For security, APNs requires you to refresh your token regularly. Refresh your token no more than once every 20 minutes and no less than once every 60 minutes.

when using Token Based Authentication. Besides storing the time at which the last token was generated in memory or some database and checking if it has been an hour since, is there anyway to automatically regenerate the authentication token?

1 Answers

So here we're talking about JWT tokens. They should have a timestamp within the payload, the "iat" ( issues at ) ("Here you have the fields"). So there are 2 cases:

  1. You're creating a new token whenever you're sending a push
  2. You're using the same token whenever you're sending a push

For case 1, you're safe, it will always be valid.

For case 2, you're only interested in the payload coz that's the custom part. But this would mean that you stored the token somewhere. If that's the case, extract the payload, replace the "iat" with now(), sign it and you should be good to go.

Related