Back to Conflicts Catalog
High SeverityContradictoryPending Review
Mismatch in Authentication Token Expiration Time
Conflict ID: conflict-token-expiryCreated: 9/12/2026, 2:30:00 PM
Side-by-Side Statement Comparison
SOURCE AOpen Document
JWT Authentication & Security Policy
AuthenticationVer: v3.0.1Updated: 9/10/2026
Document Claim / Excerpt
"JWT authentication tokens expire after 15 minutes of inactivity for maximum protection. Clients must send a refresh token request to obtain a fresh access token before expiration."
SOURCE BOpen Document
User Authentication & Session FAQ
FAQVer: v2.2.0Updated: 7/22/2026
Document Claim / Excerpt
"Session tokens remain valid for 24 hours from issuance unless manually invalidated or logged out by the end user."
AI Analysis
Automated reasoning & conflict explanation
Existing Analysis NoteStage 1 Foundation
Security Policy states JWT tokens expire after 15 minutes of inactivity, but the User Authentication FAQ informs end users that session tokens remain valid for 24 hours. This leads to user session dropouts and security misunderstandings.
AI Analysis Stage Placeholder
AI analysis will be generated in the next stage. Advanced LLM discrepancy reasoning and resolution recommendations will run here.