# Invalidate REST API token

**URL:** <https://forums.rocket.chat/t/invalidate-rest-api-token/7188>\
**Category:** Community Support\
**Created:** [June 3, 2020, 12:49pm UTC](https://forums.rocket.chat/t/invalidate-rest-api-token/7188 "2020-06-03T12:49:15Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![chris1](https://sea1.discourse-cdn.com/flex021/user_avatar/forums.rocket.chat/chris1/32/1533_2.png) [@chris1](https://forums.rocket.chat/u/chris1)\
**Post date:** [June 3, 2020, 12:49pm UTC](https://forums.rocket.chat/t/invalidate-rest-api-token/7188/1 "2020-06-03T12:49:15Z")

</div>

### Description

Hi! Is there a possibility to automatically invalidate access tokens after a period of time? I am talking about ` `rc\_token` ` which gets set as a cookie once logged in. Even if I set the “Login expiration in days” to 1 in the Admin settings, I can still do REST API calls indefinitely after 1 day by setting the ` `X-Auth-Token` ` to whatever the ` `rc\_token` ` was.

I came across this “official” answer from a [Rocket.Chat](http://rocket.chat/) employee saying ` `Currently the authentication tokens obtained via the Rocket.Chat REST API have no expiration date.` ` [(Rocket.Chat) Never expire auth token - Stack Overflow](https://stackoverflow.com/questions/45866612/rocket-chat-never-expire-auth-token/45867251#45867251)

I wonder if that changed somehow during the last 3 years 🙂 can anyone help?
