What Is the Default Logto Configuration?

Logto initializes every new tenant with built-in OIDC defaults including a 14-day session TTL, conditional refresh-token rotation for public clients, and immutable admin console flags alongside predefined ID token extended claims.

When you deploy the logto-io/logto platform, every new tenant receives a default Logto configuration that governs authentication behavior, administrative settings, and token claims. These values are hard-coded in the TypeScript source and seeded into the database during tenant creation, providing secure, production-ready defaults while remaining customizable through the Admin Console or Management API.

OIDC Provider Defaults

Located in packages/core/src/oidc/defaults.ts, the OIDC defaults define core authentication behavior for the underlying OpenID Provider.

Session and Refresh Token Policies

The default configuration implements specific session TTL and refresh token rotation logic:

  • sessionTtl: Set to 14 days (1209600 seconds), controlling how long a user session remains valid.
  • rotateRefreshToken: Rotates public-client refresh tokens unless they are older than one year or already close to expiration.
  • refreshTokenTtl: Uses custom TTL logic that respects rotated refresh tokens rather than a fixed duration.

Admin Console and ID Token Defaults

Seed data defined in packages/schemas/src/seeds/logto-config.ts establishes the initial state for administrative settings and token claims.

Immutable Admin Console Flags

Two boolean flags are frozen (cannot be mutated at runtime):

  • signInExperienceCustomized: false
  • organizationCreated: false

These flags track whether the tenant has customized its sign-in experience or created its first organization, serving as guardrails until configuration is completed through the UI.

Default ID Token Extended Claims

Out of the box, Logto enables three extended claims in ID tokens:

{
  "enabledExtendedClaims": ["roles", "organizations", "organization_roles"]
}

This configuration allows applications to immediately access user roles and organizational membership data without additional API calls.

Accessing Defaults Programmatically

You can inspect these defaults using the Logto config library at packages/core/src/libraries/logto-config.ts.

To access the OIDC defaults directly:

import defaults from '#src/oidc/defaults';

// Example: use the default session TTL for a new session cookie
const cookieMaxAge = defaults.sessionTtl; // 1209600 seconds (14 days)

To retrieve the admin console configuration via the library:

import { createLogtoConfigLibrary } from '#src/libraries/logto-config';

const configLib = createLogtoConfigLibrary({ /* …queries & pool… */ });
const adminConfig = await configLib.getJwtCustomizers(consoleLog);
// adminConfig includes the default frozen flags

To inspect the ID token extended claims:

import { createLogtoConfigLibrary } from '#src/libraries/logto-config';

const lib = createLogtoConfigLibrary({ /* … */ });
const idTokenConfig = await lib.getJwtCustomizers(consoleLog);
console.log(idTokenConfig.enabledExtendedClaims);
// → ['roles', 'organizations', 'organization_roles']

Summary

  • The default Logto configuration sets a 14-day session TTL and intelligent refresh-token rotation for public clients via packages/core/src/oidc/defaults.ts.
  • Admin console flags (signInExperienceCustomized and organizationCreated) start as false and are frozen to prevent runtime mutation.
  • ID tokens ship with extended claims for roles, organizations, and organization_roles enabled by default.
  • Access these values programmatically through the createLogtoConfigLibrary factory and direct imports from the OIDC defaults module.

Frequently Asked Questions

What is the default session TTL in Logto?

The default session TTL is 14 days (1209600 seconds). This value is defined in packages/core/src/oidc/defaults.ts and applies to all new tenants until overridden via environment variables or the Management API.

Can I modify the default admin console flags programmatically?

No. The signInExperienceCustomized and organizationCreated flags are frozen in the database seed at packages/schemas/src/seeds/logto-config.ts. They can only transition from false to true through specific user actions in the Admin Console or via sanctioned Management API endpoints, not by direct mutation.

Which extended claims are enabled in ID tokens by default?

By default, Logto enables three extended claims: roles, organizations, and organization_roles. These are seeded in packages/schemas/src/seeds/logto-config.ts and allow applications to receive user authorization context immediately upon authentication.

Where does Logto store its default OIDC configuration?

The OIDC defaults reside in packages/core/src/oidc/defaults.ts. This file exports the session TTL, refresh token rotation policies, and TTL calculation logic used by the underlying OIDC Provider.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →