Sessions
See every signed-in device, revoke one, and know when Avaloi asks for a fresh sign-in.
A session is a signed-in browser or device. Avaloi keeps it for 14 days of idle time, and at most 90 days from creation. Cookies are HttpOnly.
See your sessions
Open Account settings, then Security. Under Sessions, each row shows the browser, the last IP, and the last used time.
Revoke a session
Choose Sign out on the row. That browser signs out within seconds. Sign out everywhere else ends every session but this one.
A password reset ends every session. A password change, turning two-factor on or off, and disconnecting a sign-in method end every other session.
New devices
Under Recent activity on the same page, Avaloi lists sign-ins and failed sign-ins with their IP address. If you do not recognize one, sign out that session and change your password.
Fresh sessions
Sensitive actions need a fresh session: transferring ownership, deleting your account, revealing SFTP or database credentials, and granting destructive API scopes. Sign in again when the dashboard asks.
Limits
- 14 days idle.
- 90 days from creation.
Quick answers
I see a device I do not know. Sign it out, change your password, and turn on two-factor if you have not.
Why was I signed out after two weeks? Sessions end after 14 days without use. Sign in again.
Can a script use my session cookie? No. Cookies are for the browser. Scripts use an API key.
API
GET /v1/users/me/sessionsDELETE /v1/users/me/sessions/{id}DELETE /v1/users/me/sessions
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.