The second is controlled by the "csrf_expiration" config key in your app config file. By default it is set to zero, meaning "always generate a new token".
Note that you have to do this before you call Security::check_token() !
It looks like you're new here. If you want to get involved, click one of these buttons!