Skip to main content

Session management

Session lifecycle​

  1. Creation: A session is created when the user authenticates
  2. Activity: Last activity is updated when a token is refreshed/used
  3. Expiration: The session expires after 14 days of inactivity
  4. Revocation: Can be revoked by the user, an administrator, or security events

Session properties​

PropertyDescription
Session IDUnique identifier (GUID)
Device nameA user-friendly description of the device
Device typeMobile, Desktop, Tablet, Unknown
IP addressThe current connection's IP address
Client IDThe application that created the session
CreatedWhen the session was created
Last activityThe last token use/refresh
ExpiresThe session's expiration time

Automatic session revocation​

Sessions are automatically revoked on:

EventDescription
User sign-outA user-initiated sign-out
Password changeThe user changed their password
Password resetA password reset via email
Email changeThe user changed their email address
Enabling/disabling 2FAA change to two-factor authentication settings
Administrator actionAn administrator revoked the sessions
Session expirationA timeout due to inactivity
Security feature

On sensitive account changes (password, email, 2FA), all of the user's sessions are revoked for security reasons.

Implementing sign-out​

Frontend sign-out flow​

  1. Call the logout endpoint
  2. Clear the local tokens
  3. Redirect the user to the sign-out page
# Redirect the user to the logout endpoint
curl "https://your-sso-domain.com/connect/logout?\
id_token_hint=ID_TOKEN&\
post_logout_redirect_uri=https://yourapp.com/logged-out"

Backend sign-out (invalidating tokens)​

# Revoke the refresh token
curl -X POST https://your-sso-domain.com/connect/revoke \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "token=REFRESH_TOKEN" \
-d "token_type_hint=refresh_token" \
-d "client_id=my-app" \
-d "client_secret=my-secret"

Session API​

For programmatic (machine-to-machine) session management, use the following endpoints. They require an access token obtained via client_credentials with the api scope (user tokens cannot call them). {guid} is the user's GUID, and {sessionId} is the session's GUID.

OperationEndpoint
List a user's sessionsGET /api/sessions/user/{guid}
Revoke all of a user's sessionsDELETE /api/sessions/user/{guid}
Revoke a specific sessionDELETE /api/sessions/{sessionId}

Example – list a user's sessions:

curl https://your-sso-domain.com/api/sessions/user/USER_GUID \
-H "Authorization: Bearer M2M_ACCESS_TOKEN"

Example – revoke a specific session:

curl -X DELETE https://your-sso-domain.com/api/sessions/SESSION_ID \
-H "Authorization: Bearer M2M_ACCESS_TOKEN"