Sessions
See every signed-in device, revoke one, and know when Avaloi asks for a fresh sign-in.
A session is a signed-in browser or device. Avaloi keeps it for 14 days of idle time, and at most 90 days from creation. Cookies are HttpOnly.
See your sessions
Open User settings, then Sessions. Each row shows the device, the last IP, and the last used time.
Revoke a session
Choose Revoke on the row. That browser signs out within seconds. Revoking the current session signs you out here.
A password reset or a password change ends every other session.
New devices
Avaloi emails you when a new device signs in. If you do not recognize it, revoke it and change your password.
Fresh sessions
Sensitive actions need a fresh session: transferring ownership, deleting your account, revealing SFTP or database credentials, and granting destructive API scopes. Sign in again when the dashboard asks.
Limits
- 14 days idle.
- 90 days from creation.
Quick answers
I see a device I do not know. Revoke it, change your password, and turn on two-factor if you have not.
Why was I signed out after two weeks? Sessions end after 14 days without use. Sign in again.
Can a script use my session cookie? No. Cookies are for the browser. Scripts use an API key.
API
GET /v1/users/me/sessionsDELETE /v1/users/me/sessions/{id}
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.