Skip to content
All documentation

Session Revocation and Access Recertification

Sign out of every device, or force re-login across an organization, and review who still has access. An administrator can revoke a user's active sessions and an owner can force everyone to sign in again. Session revocation is an Enterprise feature, available throughout a free trial.

What it is

Sessions are stateless: each sign-in issues a signed token stored in an httpOnly, secure, same-site cookie. Signing out clears the cookie, but a copied or stolen token would still work until it expires. Session revocation fixes that by stamping every token with a per-user epoch, a counter that administrators can bump to instantly invalidate every outstanding sign-in for that person, on any device.

Session revocation and force re-login are Enterprise capabilities. On the Individual and Team tiers the revoke controls are hidden in the admin roster and the server returns a 403 if the action is requested directly. During a free trial the level of the org's effective entitlements covers the feature, so prospects can evaluate it before upgrading.

Use

  • Sign yourself out of every device at once: sign out normally, or use the sign-out-everywhere action, which also invalidates any copies of your session.
  • Revoke one person's sessions: in Admin, Members, choose Revoke sessions next to a member. Every device they are signed in on stops working immediately.
  • Force re-login organization-wide: an owner can use Force re-login in Admin, Members to invalidate every member's current session at once.
  • Review access: the member list shows each person's role and last login time, so you can verify who still needs access and revoke it for anyone who should not have it.

Security

  • The revocation check runs on the server on every request: a token is rejected the moment its epoch no longer matches the account, even if the cookie was not cleared.
  • A lower role can never revoke a higher role's sessions. An admin can revoke members only; only the owner can revoke another admin, and the owner's own sessions are revoked only by the owner.
  • Force re-login is owner-only, and it never logs out the owner performing the action, so an administrator's own session remains available.
  • Every session token also carries an absolute maximum lifetime, so even a token that is never explicitly revoked eventually expires on its own.