How Handoff Token Expiration Works
How Handoff Token Expiration Works describes a current QCUI 1.0.03 implementation detail that matters when you are validating security, session isolation, or support behavior.
Configured lifetime
The plugin reads Handoff token lifetime (seconds), clamps it to 30–300 seconds, and defaults to 60 seconds. The token row stores UTC created_at and expires_at.
Consume condition
The frontend query requires expires_at to be at or after the current UTC time. Once expired, the raw token cannot switch identities even if it was never used.
Choose the shortest practical value
Keep enough time for the new tab/browser security layers to post the handoff, but do not lengthen the window merely for convenience. Most sites should leave the 60-second default.
Security boundary
The controls described for How Handoff Token Expiration Works are complementary. Super-User authorization does not make a reusable token safe; a one-time token does not make Shared Sessions safe; and a visible banner does not make state-changing customer actions harmless. Preserve the complete 1.0.03 security model rather than removing individual checks for convenience.
Community Discussion
Want to compare support workflows, share practical tips, or discuss how you use this QCUI feature? Visit the QC User Impersonation Community. For private support, bug reports, account-specific issues, or feature requests, use the QuantaCade support system.