What do you mean by SSO token "timeout" in a typical SSO solution?
1) The SSO token is auto-refreshed after this "timeout"
2) The duration after which the newly created SSO token will expire or will be invalid for any further use for SSO. After this timeout, the user has to re-login/re-authenticate himself using his credentials
3) The duration after which the newly created SSO token will be activated for use in SSO.
4) There is no concept such as timeout for SSO token