see link to FCA guidance) | Long-lived refresh token from 22nd September 2022 | AIS consents created after 22nd September 2022 - TPPs will be issued with long-lived refresh tokens, which will have a ten-year (3,650 days) expiry date, unless a shorter expiry date is provided by the AISP. This will allow them to refresh Access Tokens for a period of 10 years without requiring customer re-authentication. Existing AIS consents will require a final re-authentication, where TPPs will present a valid short-lived refresh token (90 days) at which point they will be issued with a long-lived token, which will have a ten-year expiry date, unless a shorter expiry date is provided by the AISP. *No further authentication will be required during the ten-year period, unless • there is suspected fraud or unauthorised access or • a PSU has revoked the access *We reserve the right to request re-authentication of AIS consents for reasons including, but not limited to, the above stated reasons |
---|