> ## Documentation Index
> Fetch the complete documentation index at: https://developer.suki.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Suki Token Expired During a Long Session

> Refresh the 1 hour Suki Token on Partner APIs, or keep SDK Partner Token refresh working

After Login, Partner APIs use a **Suki Token**. You send the Login response value as the `sdp_suki_token` header. That token lasts **1 hour**. Long ambient, Form filling, Dictation, or Patient Summary jobs can outlive that window and fail with **401** / `invalid_sdp_token`.

## Partner APIs vs SDKs

| Integration | Lifetime | How refresh works |
| :- | :- | :- |
| Partner APIs (Ambient, Dictation, Form filling API, Patient Summary) | **1 hour** | Call [Login](/api-reference/authentication/login) again with a valid Partner Token (`partner_id` and `partner_token`). Replace the cached `sdp_suki_token` |
| Web SDK / `SukiAuthManager` | SDK-managed | The SDK refreshes in the background using the `partnerToken` you provided. Keep that Partner Token valid, or call `setPartnerToken` when your EHR rotates it |
| Headless Web SDK | SDK-managed | Pass a fresh Partner Token with `updatePartnerToken()` when your host app issues a new token |

<Note>
  A Partner Token alone is not enough to create sessions, stream audio, or retrieve Form filling or Patient Summary output. Exchange it for a Suki Token first (Login on Partner APIs, or SDK sign-in).
</Note>

## Common causes

* A session, poll loop, or WebSocket stays open longer than 1 hour.
* Your server caches Login and never calls Login again.
* You refresh the Partner Token in the EHR but never exchange it for a new Suki Token on Partner API clients.
* On SDKs, the Partner Token expired, so automatic Suki access token refresh fails.

## Fix Partner API clients

<Steps>
  <Step title="Plan for the 1 Hour Lifetime">
    Refresh before the hour ends, or as soon as you get `invalid_sdp_token` / **401** on a provider-scoped endpoint.
  </Step>

  <Step title="Call Login Again">
    POST `/api/v1/auth/login` with a valid `partner_id` and `partner_token` (and `provider_id` when your partner type requires it). Read the new `suki_token`.
  </Step>

  <Step title="Update Headers and New Connections">
    Set `sdp_suki_token` on later REST calls and on new WebSocket connections. Do not keep the expired value.
  </Step>
</Steps>

<Warning>
  Refreshing only the Partner Token does not update Partner API authorization. Call Login again (or let the SDK refresh) so callers get a new Suki Token.
</Warning>

## Fix SDK clients

<Steps>
  <Step title="Keep the Partner Token Valid">
    Automatic Suki access token refresh uses the current `partnerToken`. If that JWT is expired, refresh fails and API calls fail.
  </Step>

  <Step title="Rotate Partner Token at Runtime">
    **Web SDK:** Call `setPartnerToken` when your EHR issues a new Partner Token.

    **Headless Web SDK:** Call `updatePartnerToken()` with the new Partner Token.
  </Step>
</Steps>

## Next steps

<Icon icon="file-lines" iconType="solid" /> **[Partner authentication](/documentation/how-to/partner-authentication)** - Token exchange and 1 hour Suki Token lifetime

<Icon icon="file-lines" iconType="solid" /> **[Login](/api-reference/authentication/login)** - Obtain and refresh `suki_token` / `sdp_suki_token`

<Icon icon="file-lines" iconType="solid" /> **[Form filling API authentication](/form-filling-api-reference/authentication)** - Register, Login, and 1 hour refresh for Form filling APIs

<Icon icon="file-lines" iconType="solid" /> **[Web SDK token refresh](/web-sdk/guides/token-refresh)** - Automatic Suki access token refresh and `setPartnerToken`

<Icon icon="file-lines" iconType="solid" /> **[401 Unauthorized or invalid Partner Token](/documentation/troubleshooting/invalid-partner-token-401)** - Partner Token failures vs `invalid_sdp_token`
