Reported August 2026
IBMhash table

Expiring Authentication Token Manager

Reported by candidates from IBM's online assessment. Pattern, common pitfall, and the honest play if you blank under the timer.

Get StealthCoderRuns invisibly during the live IBM OA. Under 2s to a working solution.
Founder's read

IBM sent this one out in August 2026, and the detail that trips people is the boundary: a token with expiration time 4 is already dead at time 4. The problem is Expiring Authentication Token Manager. You get a timeToLive and a list of GENERATE, RENEW and COUNT operations, and you return one number per COUNT. It's a hash map simulation with a strict greater-than check. Nothing exotic, but off-by-one mistakes sink people who rush. If you blank during the live OA, StealthCoder runs invisibly as a safety net and hands you the approach.

The problem

You are given a token lifetime timeToLive and an ordered array of authentication-manager operations operations.
Each operation is an array of three strings: [type, tokenId, currentTime]. The supported operation types are:
GENERATE: create the unique token tokenId at currentTime. Its expiration time becomes currentTime + timeToLive.
RENEW: if tokenId exists and is unexpired at currentTime, reset its expiration time to currentTime + timeToLive. Otherwise, ignore the operation.
COUNT: count the tokens that are unexpired at currentTime. For this operation, tokenId is the empty string.
A token is unexpired at time t exactly when its expiration time is strictly greater than t. Therefore, a token is already expired at the instant equal to its expiration time.
Return one count for every COUNT operation, preserving query order. GENERATE and RENEW operations do not add values to the returned array.

Function
countUnexpiredTokens(timeToLive: int, operations: String[][]) → int[]

Examples
Example 1
timeToLive = 5
operations = [["GENERATE","aaa","1"],["RENEW","aaa","2"],["COUNT","","6"],["GENERATE","bbb","7"],["RENEW","aaa","8"],["RENEW","bbb","10"],["COUNT","","12"]]
return = [1,1]
Token aaa first expires at time 6, then renewal at time 2 moves its expiration to 7, so the count at time 6 is 1. It is expired by time 8, so that renewal is ignored. Token bbb is renewed from expiration time 12 to 15, so the count at time 12 is also 1.
Example 2
timeToLive = 3
operations = [["GENERATE","alpha","1"],["COUNT","","3"],["COUNT","","4"]]
return = [1,0]
Token alpha expires at time 4. It is unexpired at time 3 but expired at time 4.
Example 3
timeToLive = 4
operations = [["RENEW","ghost","1"],["GENERATE","x","2"],["GENERATE","y","3"],["RENEW","x","4"],["COUNT","","5"],["COUNT","","7"],["COUNT","","8"]]
return = [2,1,0]
Renewing the missing token ghost has no effect. Renewal moves token x's expiration to time 8, while token y expires at time 7. The three counts are therefore 2, 1, and 0.

Constraints
1 <= timeToLive <= 10^8.
1 <= operations.length <= 2000.
Every operation contains exactly three strings and uses one of GENERATE, RENEW, or COUNT.
Every non-empty tokenId contains from 1 through 10 lowercase English letters.
Every token ID used by GENERATE is unique.
Operation times are decimal integers from 1 through 10^8 and are strictly increasing across the array.

Reported by candidates. Source: FastPrep

Pattern and pitfall

Store a hash map from tokenId to expiration time. GENERATE sets map[id] = t + timeToLive. RENEW checks that the id exists and map[id] > t, then resets it to t + timeToLive. Otherwise ignore it. COUNT loops over the map and counts entries with expiration > t. With at most 2000 operations, that O(n^2) worst case is fine, so don't build a heap or a sorted structure you don't need. The pitfall is the boundary. Use strictly greater, not greater-or-equal, or Example 2 returns 1 instead of 0 at time 4. Another trap is parsing: the times arrive as strings, so convert them to integers before comparing, or you'll compare lexicographically. Also remember COUNT has an empty tokenId and shouldn't touch the map. If the boundary logic slips under pressure, StealthCoder is the hedge that catches it live.

Drill it cold or hedge it with StealthCoder. Either way, don't walk into the OA hoping you remember the trick.

If this hits your live OA

You can drill Expiring Authentication Token Manager cold, or you can hedge it. StealthCoder runs invisibly during screen share and surfaces a working solution in under 2 seconds. The proctor sees the IDE. They don't see what's behind it. Made for the candidate who got the OA invite this morning and has 72 hours, not six months.

Get StealthCoder

Related leaked OAs

⏵ Practice the LeetCode equivalent

This OA pattern shows up on LeetCode as design authentication manager. If you have time before the OA, drill that.

⏵ The honest play

You've seen the question. Make sure you actually pass IBM's OA.

IBM reuses patterns across OAs. Made for the candidate who got the OA invite this morning and has 72 hours, not six months. Works on HackerRank, CodeSignal, CoderPad, and Karat.

Expiring Authentication Token Manager FAQ

How hard is the IBM Expiring Authentication Token Manager problem really?+

Easy to low-medium. The logic is a hash map and a comparison. The difficulty is reading the spec carefully, especially that a token expires exactly at its expiration time, and that RENEW on an expired or missing token does nothing.

What's the trick to this problem?+

Use a map of tokenId to expiration time and treat unexpired as expiration strictly greater than the current time. Everything else is direct simulation. No heap or sorting is required given the small operation count.

Do I need an efficient COUNT, like a heap or sorted structure?+

No. Operations max out at 2000, so scanning the whole map on each COUNT is fast enough. A smarter structure adds bug risk for no gain. Keep it simple and get the boundary right.

What edge cases should I test before submitting?+

Test a COUNT exactly at an expiration time, which should exclude that token. Test RENEW on a missing token, RENEW on an expired token, and a renewal that extends a token past another one's expiry. Also confirm times are parsed as integers.

How do I prepare for this in 48 hours?+

Write this one from scratch twice with a hash map and walk through the three examples by hand. Then do a few other simulation problems with time boundaries, like cache expiry or rate limiters. The pattern repeats often in OAs.

Problem reported by candidates from a real Online Assessment. Sourced from a publicly-available candidate-aggregated repository. Not affiliated with IBM.

OA at IBM?
Invisible during screen share
Get it