You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

IdentityServer4引用令牌存储位置及重启后有效性问询

Answers to IdentityServer4 Reference Token Questions

1. Where does IdentityServer4 store reference tokens?

By default, IdentityServer4 stores reference tokens in an in-memory cache (backed by the IMemoryCache service). This is transient storage—tokens only exist while the IdentityServer instance is running and are lost when the service restarts or scales to new instances.

For persistent storage (so tokens survive restarts or work across multiple IdentityServer nodes), you have two primary options:

  • Use the official Entity Framework integration: This stores reference tokens (and other persisted grants like refresh tokens) in a database, typically in a PersistedGrants table.
  • Implement your own IPersistedGrantStore: This interface defines methods for storing, retrieving, and deleting persisted grants. You can plug in any storage system you prefer—like Redis, a custom SQL database, or a NoSQL store—by implementing these methods.

2. Will a reference token remain valid after IdentityServer4 restarts? (And how to fix if not)

Short answer: By default, no—it will be invalid.

Here's the breakdown:
When using the default in-memory store, all reference tokens are cleared when IdentityServer restarts. When a client sends the reference token for validation, IdentityServer checks its store to confirm the token exists, hasn't expired, and is still valid. Since the in-memory store is empty after a restart, it can't locate the token and will reject the request.

Note: Your IResourceOwnerPasswordValidator implementation only handles validating user credentials during login—it doesn't affect how tokens are stored or validated post-login.

How to solve this: Implement a persistent IPersistedGrantStore

To make reference tokens survive restarts, replace the in-memory store with a persistent one:

  1. Implement the IPersistedGrantStore interface: This interface includes methods like StoreAsync, GetAsync, RemoveAsync, and GetAllAsync to manage CRUD operations for persisted grants (including reference tokens).

    • For example, with Redis, you'd write code to save tokens with their expiration time, retrieve them by their unique key, and delete them when they expire or are revoked.
    • For a SQL database, create a table to store grant details (like grant key, client ID, user ID, expiration date, grant type) and map the interface methods to database queries.
  2. Register your custom store in dependency injection: Update your IdentityServer startup configuration to use your persistent store instead of the default in-memory one:

    services.AddIdentityServer()
        .AddInMemoryClients(Config.Clients)
        .AddInMemoryApiResources(Config.ApiResources)
        .AddResourceOwnerValidator<MyCustomPasswordValidator>()
        .AddPersistedGrantStore<MyCustomPersistedGrantStore>(); // Register your custom store
    

Once set up, reference tokens are stored in your persistent system. After a restart, IdentityServer can fetch the token from this store, verify its validity and expiration, and grant access if everything checks out.


内容的提问来源于stack exchange,提问作者eugeneK

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.15 04:52:29