In Part 1 we setup basic token authentication using JWT’s with asp.net. Things are setup reasonably but all is not well. As a developer, you could give the token a lifespan of 30 days and just force the user to re-login after those days but what if you make the user inactive and don’t want him to login anymore? There must be better way.
Generally, I token has a lifetime of about an hour and when it expires, we want to refresh that token, verifying that the user still has access to the system, etc. The method that this is handled is using refresh tokens. A refresh token is returned along with the normal token and it’s stored for when we must refresh normal token.
This will require us to track refresh tokens in our database, so first, let’s create the RefreshToken model.