# How long should my SSO tokens live? _Category: Domain, access and SEO_ Short: 300 seconds (5 minutes) is a good default, and it's what the **Token TTL** setting recommends. A token only has to live long enough to reach HelpCenter.io. Your Login URL redirects the reader straight to `/sso/jwt`, so a few minutes leaves plenty of room, and once the reader is signed in the token isn't needed again. - **Sign-in keys work once.** The `key` HelpCenter.io sends to your Login URL is good for one sign-in, so a longer token life gives readers nothing extra. It only widens the window in which a leaked token could be used. - **Token TTL caps widget tokens only.** The widget rejects tokens older than your Token TTL (30 to 86,400 seconds), even if their `exp` is later. For sign-in through your Login URL or an iframe, `exp` is the only limit, so keep it short on your side. - **The widget gets fresh tokens on its own.** It asks your `onAuthExpired` function for a new one when it needs it, so short tokens don't bother your readers. - **The token's life isn't the sign-in's life.** Once a reader is signed in to your help center, **Reader sign-in lasts** decides how long they stay signed in: from 1 hour to 30 days, 24 hours by default. See [Sign readers in with your own login (JWT SSO)](https://self.helpcenter.io/content/jwt-sso). - **Clocks matter.** `exp` is required, and HelpCenter.io allows 30 seconds of difference on `iat` and `exp`. Keep your server's clock in sync, for example with NTP. The full rules are in [JWT claims and validation rules](https://developers.helpcenter.io/content/jwt-claims) on the developer portal. ## Related articles - [Sign readers in with your own login (JWT SSO)](https://self.helpcenter.io/content/jwt-sso) - [Sign readers into the widget with a JWT](https://developers.helpcenter.io/content/widget-jwt) on the developer portal