← 문제 라이브러리
Security Beginner 3 min

jwt expired (401): every request fails after about an hour in the app

Recognise token expiry and the missing refresh step.

무료
시나리오

About an hour after opening the mobile app every screen fails; logging in again fixes it. The API logs '401 GET /api/feed reason="TokenExpiredError: jwt expired"'.

먼저 볼 것
  • Understand the main investigation order for Security incidents.
  • Separate user-facing symptoms from the deeper technical cause.
  • Describe both quick recovery actions and follow-up improvements.
점검 체크리스트
  1. Summarize the symptom and the current impact first.
  2. Check recent changes before collecting deeper diagnostics.
  3. Verify config, runtime state, and recovery path in order.
복구와 재발 방지

Write down the minimal recovery path first, then capture the improvements that reduce repeat incidents.

같이 보면 좋은 질문
Should I translate commands, logs, or product names?

No. Keep commands, logs, file names, APIs, and product names unchanged, then explain the reasoning in the selected UI language.

What should the answer focus on?

State the root cause, the evidence that supports it, and the safest recovery direction.

Why can the scenario remain in the original language?

The source scenario is treated as an incident artifact. Guidance, checklist, hints, and explanations can be localized around it.