Configuration
With the settings feature, data provider admins can configure the following settings:
The Configuration page offers to options for settings: API Settings and Customer Authentication. Use the following instructions to get started with both.
API Settings
On the API Settings section, select the Edit button to change Public URLs and tokens.
You can update your Public URL for your intermediary. You'll also want to update the token expiration.

Public URL
This enables you to set the redirect URL where end users are authenticated.
Any time this URL is changed, your DNS settings must be updated accordingly.
Token Settings
This is where you can set how long the access and refresh tokens remain valid.
The default setting is 10 minutes for access tokens and 30 days for refresh tokens.
The max duration for access tokens is 10 minutes.
If the refresh token expires, the end user will have to reauthenticate.
Customer Authentication
This is where your institution’s identity provider (IdP) information is given for customer authentication. This is how end users authenticate to grant consent to share their data.
A client ID, client secret, and discovery URI are required and must be obtained from your IdP and entered here. The rest of the fields are required only if the discovery URI is unavailable.
Customer OIDC is required.