Hi, it's up to Keycloak admins to define the session expiration time. If "SSO Session Max" parameter is set to "10 hours", there's a good chance that this is still the default configuration... Like many other things in Keycloak such as "brute force detection" disabled, "roles" scope by default, etc...