Session management
Session lifecycle
- Creation: A session is created when the user authenticates
- Activity: Last activity is updated when a token is refreshed/used
- Expiration: The session expires after 14 days of inactivity
- Revocation: Can be revoked by the user, an administrator, or security events
Session properties
| Property | Description |
|---|---|
| Session ID | Unique identifier (GUID) |
| Device name | A user-friendly description of the device |
| Device type | Mobile, Desktop, Tablet, Unknown |
| IP address | The current connection's IP address |
| Client ID | The application that created the session |
| Created | When the session was created |
| Last activity | The last token use/refresh |
| Expires | The session's expiration time |
Automatic session revocation
Sessions are automatically revoked on:
| Event | Description |
|---|---|
| User sign-out | A user-initiated sign-out |
| Password change | The user changed their password |
| Password reset | A password reset via email |
| Email change | The user changed their email address |
| Enabling/disabling 2FA | A change to two-factor authentication settings |
| Administrator action | An administrator revoked the sessions |
| Session expiration | A timeout due to inactivity |
Security feature
On sensitive account changes (password, email, 2FA), all of the user's sessions are revoked for security reasons.
Implementing sign-out
Frontend sign-out flow
- Call the logout endpoint
- Clear the local tokens
- Redirect the user to the sign-out page
# Redirect the user to the logout endpoint
curl "https://your-sso-domain.com/connect/logout?\
id_token_hint=ID_TOKEN&\
post_logout_redirect_uri=https://yourapp.com/logged-out"
Backend sign-out (invalidating tokens)
# Revoke the refresh token
curl -X POST https://your-sso-domain.com/connect/revoke \
-H "Content-Type: application/x-www-form-urlencoded" \
-d "token=REFRESH_TOKEN" \
-d "token_type_hint=refresh_token" \
-d "client_id=my-app" \
-d "client_secret=my-secret"
Session API
For programmatic (machine-to-machine) session management, use the following endpoints. They require an access token obtained via client_credentials with the api scope (user tokens cannot call them). {guid} is the user's GUID, and {sessionId} is the session's GUID.
| Operation | Endpoint |
|---|---|
| List a user's sessions | GET /api/sessions/user/{guid} |
| Revoke all of a user's sessions | DELETE /api/sessions/user/{guid} |
| Revoke a specific session | DELETE /api/sessions/{sessionId} |
Example – list a user's sessions:
curl https://your-sso-domain.com/api/sessions/user/USER_GUID \
-H "Authorization: Bearer M2M_ACCESS_TOKEN"
Example – revoke a specific session:
curl -X DELETE https://your-sso-domain.com/api/sessions/SESSION_ID \
-H "Authorization: Bearer M2M_ACCESS_TOKEN"