Token refresh not refreshing acr in access token?

157 views
Skip to first unread message

Lovis Möller

unread,
Dec 20, 2022, 11:04:12 AM12/20/22
to Keycloak User
Hi everyone,

I've implemented step-up authentication with LoA/acr.
It works fine, but when a token is refreshed using a refresh token, the "acr" field in the access token stays the same, even if the configured maxAge for the "Condition - Level Of Authentication" was reached. 
Is there anything I need to do differently, is this intended, or maybe even a bug? 
I'm using keycloak.js for the login and token refresh.

Thanks in advance!
Reply all
Reply to author
Forward
0 new messages