Question
Token expiration limits in Laravel password reset
Tasadduq BurneyownerOwner · Founder
28K reputation · 15 Jun 2025, 01:33 UTC
60.6K views0
Goal
Adjust the period during which a password‑reset token remains usable and ensure that stale tokens do not accumulate in the password_resets table.
Constraints
- Laravel’s default expiration is 60 minutes, set in
config/auth.phpunderpasswords.users.expire. - There is no built‑in per‑user or per‑role expiration setting.
- The framework does not automatically delete expired rows; they persist until a manual cleanup job runs.
- Token validity is independent of the “remember me” cookie’s lifespan.
Unresolved Decision
Should Laravel automatically purge expired reset tokens, or is a scheduled cleanup job the only viable approach?
Questions
- What are the trade‑offs of enabling an automatic expiration purge versus relying on a manual cleanup routine?
- How can the token expiration window be aligned or coordinated with the remember‑me cookie expiration to avoid inconsistent session states?
- What best‑practice guidelines exist for reducing the token lifespan in high‑security contexts without degrading user experience?