Skip to content

When logging into APIML with an expired apiml token it throws a 400 to the user #4618

@Joe-Winchester

Description

@Joe-Winchester

Describe the bug
Log into APIML and go home over the weekend - the apiml token expires !
Come back in on Monday and can log into the gateway and get a 400

Image

Looking at the Zowe logs it is because the apimlAuthenticationToken JWT has expired

2026-05-11 09:18:54.723 <ZWEAGW1:reactor-http-nio-3:33557110> �[35mZWESVUSR�[0;39m �[36mDEBUG�[0;39m ((o.z.a.g.l.DeterministicLoadBalancer)) Exception when trying to parse the JWT token eyJ0eXAiOiJKV1QC.......8mugPBQh2t93LKpwFM: JWT Token is expired

I can log into a private browser and/or delete the apimlAuthenticationToken

Expected behavior
I'd like the APIML to detect the expired token and delete the cookie data and allow me to log back in again

Metadata

Metadata

Assignees

Labels

bugVerified defect in functionalityclarificationIssue is being clarified in the discussion with the creator of the issue

Type

No type
No fields configured for issues without a type.

Projects

Status
Blocked

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions