Sessions
One session per device. Visible across clients, and revocable when you need it.
When a user signs in, pr0d issues a session for that device. A user on a laptop and a phone has two sessions, and either can be ended without touching the other.
What a session holds
A session belongs to one user and one application. It records the device it was issued to and the audiences it is valid for, and it carries a status that your application can check.
{
"session_id": "ses_demo_01",
"subject": "usr_demo_01",
"application": "example-app",
"audience": ["example-api", "example-gateway"],
"device": "web",
"status": "active",
"token_type": "opaque"
}Tokens are opaque: they carry no claims of their own, so nothing about the user is exposed if one leaks, and revoking a session takes effect immediately.
Renewal
Sessions renew on foreground activity. A user who keeps using your app stays signed in; one who stops is signed out when the session lapses.
Revocation
Any session can be revoked, by the user from a list of their devices or by your application. A revoked session stops working at once; the next request from that device is treated as signed out.
Illustrative schema
The fields above show the shape of a session. The exact API contract is documented in the API reference as it ships.