answering my own question: here is a statement from an auth0 person confirming that login tokens are impossible to revoke:
Is there any way to expire or revoke bearer access token on logout event of dot net core application
Related topics
| Topic | Replies | Views | Activity | |
|---|---|---|---|---|
| Expire access token when Logout | 2 | 8092 | July 19, 2024 | |
| Any way to kill a token upon logout? (2020 edition) | 1 | 4713 | March 6, 2020 | |
| Current user token still be validating with JWT in web api even though user signout from the client application (angujar js 1.x) | 1 | 4336 | December 29, 2017 | |
| Is there any way to expire or update token time on logout in springboot Project | 1 | 1584 | December 23, 2022 | |
| When a user's third-party consented access_token expires | 2 | 2820 | January 6, 2021 |