Does the authorization code in OAuth 2.0 (3LO) for Confluence DC expire?

Hi team,

We are setting up a connection from external apps to Confluence DC using OAuth 2.0 (this document: https://confluence.atlassian.com/confkb/oauth-2-0-configuration-for-confluence-1224638905.html).
I would like to confirm:

  • Does the authorization code (returned as the code parameter of the redirect_uri after user consent) have an expiration time?

  • If yes, how long is it valid before it expires?

  • Is this consistent across all Atlassian products (Jira, Confluence, etc.)?

Thanks in advance for the clarification!

1 Like