How is the service being used? i.e. what client?
A session cookie is returned when a client connects to IS. If the session is not used for the session timeout time, the session will expire and, therefore, the cookie will no longer be valid.
Depending on your application you may want to increase the session timeout time.
Or you may want to make sure clients really do a login (without the cookie) before executing IS services.
HTH,
Fred
#webMethods-General#Integration-Server-and-ESB#webMethods