# Question on refreshing auth tokens

**URL:** <https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723>\
**Category:** Game Design\
**Tags:** server-framework\
**Created:** [May 11, 2020, 5:07pm UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723 "2020-05-11T17:07:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![antoniocapizzi95](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/antoniocapizzi95/32/234_2.png) [@antoniocapizzi95](https://forum.heroiclabs.com/u/antoniocapizzi95)\
**Post date:** [May 11, 2020, 5:07pm UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723/1 "2020-05-11T17:07:30Z")

</div>

Hi everyone, I read a post written few months ago in which a user was advised to create a runtime RPC function that generates a new token to exchange with the existing one to refresh the token.  
I wanted to understand, the function to use in the runtime code is “nk.authenticate\_token\_generate(user\_id, username)” ?  
Then, client side how do I modify the session to insert the new token?  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![zyro](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/zyro/32/14_2.png) [@zyro](https://forum.heroiclabs.com/u/zyro)\
**Post date:** [May 12, 2020, 12:51pm UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723/2 "2020-05-12T12:51:47Z")

</div>

It would help to know which client library you’re using? I believe all of them should have a function that restores a session from a token string. Normally this is used when reading a stored session at game startup, but it can be used to restore a session from a string received from an RPC response.

---

<div class="post-metadata">

**Author:** ![antoniocapizzi95](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/antoniocapizzi95/32/234_2.png) [@antoniocapizzi95](https://forum.heroiclabs.com/u/antoniocapizzi95)\
**Post date:** [May 12, 2020, 1:17pm UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723/3 "2020-05-12T13:17:10Z")

</div>

I’m using Unity client side.  
Unfortunately in the documentation I have not found the function that restores the session.  
Is the function I use in the runtime code correct?  
Thanks.

---

<div class="post-metadata">

**Author:** ![zyro](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/zyro/32/14_2.png) [@zyro](https://forum.heroiclabs.com/u/zyro)\
**Post date:** [May 12, 2020, 1:22pm UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723/4 "2020-05-12T13:22:29Z")

</div>

You probably want to use [this function](https://github.com/heroiclabs/nakama-dotnet/blob/master/src/Nakama/Session.cs#L101). Yes, the `nk.authenticate_token_generate` runtime function will give you a valid session token.

---

<div class="post-metadata">

**Author:** ![antoniocapizzi95](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/antoniocapizzi95/32/234_2.png) [@antoniocapizzi95](https://forum.heroiclabs.com/u/antoniocapizzi95)\
**Post date:** [May 12, 2020, 1:27pm UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723/5 "2020-05-12T13:27:36Z")

</div>

Thanks, I’ll try this function.

---

<div class="post-metadata">

**Author:** ![antoniocapizzi95](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/antoniocapizzi95/32/234_2.png) [@antoniocapizzi95](https://forum.heroiclabs.com/u/antoniocapizzi95)\
**Post date:** [May 12, 2020, 4:11pm UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723/6 "2020-05-12T16:11:40Z")

</div>

I have another question: I created the runtime function that generates a new token to replace an expired token, but there is a problem: if my current token is expired I can’t run the rpc function to get the new one.  
How can I fix this problem?  
Thanks again.

---

<div class="post-metadata">

**Author:** ![novabyte](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/novabyte/32/1324_2.png) [@novabyte](https://forum.heroiclabs.com/u/novabyte)\
**Post date:** [May 13, 2020, 8:04am UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723/7 "2020-05-13T08:04:56Z")

</div>

@antoniocapizzi95 I would recommend you try to think about the problem to solve more deeply. The solution is quite straightforward:

1. Make sure that you’ve configured the `session.token_expiry_sec` option in the server to use a token lifetime that makes sense for your game. Maybe 1 day or 7 days or really whatever balance you want to strike between convenience for the player and re-authentication (depending on what authentication options you’re using with Nakama).
2. Attempt to refresh the token some number of hours before it expires. This is easy and cheap as an operation to perform so there’s no real harm in how long you leave it before you refresh the token.
3. If the session token has expired (maybe because the player hasn’t played in a while) you re-authenticate the player like you would have to do anyway.

I believe the 3 steps above cover all scenarios around token lifetimes. Hope this helps.

---

<div class="post-metadata">

**Author:** ![antoniocapizzi95](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.heroiclabs.com/antoniocapizzi95/32/234_2.png) [@antoniocapizzi95](https://forum.heroiclabs.com/u/antoniocapizzi95)\
**Post date:** [May 18, 2020, 3:22pm UTC](https://forum.heroiclabs.com/t/question-on-refreshing-auth-tokens/723/8 "2020-05-18T15:22:58Z")

</div>

Thanks for the information you gave me. I solved it.  
I have another question. Is there a direct way to revoke a token? I mean other than waiting for the deadline ( `session.token_expiry_sec`).
