pr0dDOCS
Identity

Sessions

One session per device. Visible across clients, and revocable when you need it.

When a user signs in, pr0d issues a session for that device. A user on a laptop and a phone has two sessions, and either can be ended without touching the other.

What a session holds

A session belongs to one user and one application. It records the device it was issued to and the audiences it is valid for, and it carries a status that your application can check.

{
  "session_id": "ses_demo_01",
  "subject": "usr_demo_01",
  "application": "example-app",
  "audience": ["example-api", "example-gateway"],
  "device": "web",
  "status": "active",
  "token_type": "opaque"
}

Tokens are opaque: they carry no claims of their own, so nothing about the user is exposed if one leaks, and revoking a session takes effect immediately.

Renewal

Sessions renew on foreground activity. A user who keeps using your app stays signed in; one who stops is signed out when the session lapses.

Revocation

Any session can be revoked, by the user from a list of their devices or by your application. A revoked session stops working at once; the next request from that device is treated as signed out.

Illustrative schema

The fields above show the shape of a session. The exact API contract is documented in the API reference as it ships.

On this page