← Auth / Security

Session Management

auth / security · wireframes · user-facing loading

Devices where the account is signed in, and ending sessions you no longer need.

Wireframe
  1. 1 The current session can't be ended — instead of "Revoke" it carries a "This session" status chip.
  2. 2 Device and location are approximate (VPNs and proxies skew them) and are no proof of identity.
  3. 3 "Revoke" ends the session on that device; behind a confirmation (confirm-dialog), re-auth — v2. Mechanics — ending a session.
  4. 4 "End all other sessions" signs out on every device except the current one; also behind a confirmation.
  5. 5 The concurrent-session limit v2 — 5 by default, configurable in the Admin Panel. When exceeded, the oldest session ends automatically. Policy — Concurrent sessions.
  6. 6 The new-device sign-in alert v2 — a banner plus an email. "This wasn't me" leads to a password change.