Revoking access tokens
-
Is there a mechanism by which and
access_token
/id_token
can be revoked upon user password change? I'm looking for something similar to howrefresh_token
s are revoked when that occurs. -
No, those tokens are completely de-coupled from FusionAuth (in a fundamental way, that is the point of those tokens).
There are revocation strategies however, but they require some additional work.
Here is one strategy we have documented: https://fusionauth.io/learn/expert-advice/tokens/revoking-jwts/