1
Manage Vault leases
medium
A platform team runs a Vault cluster with a transit secrets engine mount at transit/. An application holds a token with a policy granting only "update" on transit/encrypt/orders and "read" on transit/keys/orders. The application's token has a TTL of 1h with a max_ttl of 4h, and it renews itself every 30 minutes using the token renewal endpoint. After roughly four hours of continuous operation, the application's API calls begin failing with a permission denied error even though the token was renewed successfully each time. Which Vault behavior explains this failure?