> **Can't find what you're looking for?** Use `search_docs` on the docs MCP server at `https://www.openfort.io/api/mcp` to find what you need.
>
> **Have feedback?** Use `submit_feedback` on the same MCP server.

# User Sessions

## Session overview

A session is created when a user signs in. By default, sessions last **30 days** and a user can have an unlimited number of active sessions.

A session is represented by a signed session token. By default the SDK stores it in browser storage and sends it as a bearer token; a project can instead keep it in a first-party HttpOnly cookie on its own domain, see [Cookie sessions](https://www.openfort.io/docs/configuration/cookie-sessions).

## Automatic session refresh

Openfort uses a **sliding session** model:

* Sessions automatically extend when the user makes authenticated requests
* If a session is accessed within its refresh window (one day before potential refresh), the expiration extends
* No manual "refresh token" exchange is required
* If a session hasn't been accessed for 30 days, it expires

This approach balances security (sessions eventually expire) with convenience (active users stay logged in).

## Session termination

A session terminates when:

* The user clicks sign out
* The session reaches its maximum lifetime (30 days without activity)
* The session is explicitly revoked

Changing or resetting a password does not revoke the user's other sessions by default.

### Session token format

Session tokens are:

* Randomly generated unique identifiers (32 characters)
* Signed using HMAC-SHA-256 with your project's secret
* Stored in browser storage by default, or in a secure, HttpOnly `openfort.session_token` cookie for projects using [cookie sessions](https://www.openfort.io/docs/configuration/cookie-sessions)
* Verified against Openfort's servers on each request

The token format is `{token}.{signature}`, where the signature ensures the token hasn't been tampered with.

## Authorizing requests with the session token

To include the current user's session token on requests to your backend, use the `getAccessToken()` method. The SDK handles token management internally. With cookie sessions, `getAccessToken()` returns `null` and the browser sends the cookie to your backend by itself.

```ts
const accessToken = await openfort.getAccessToken();

const response = await fetch(<your-api-route>, {
    method: <your-request-method>
    body: <your-request-body>,
    headers: {
        'Authorization': `Bearer ${accessToken}`,
        /* Add any other request headers you'd like */
    }
});
```

* [Verify tokens server-side](https://www.openfort.io/docs/products/embedded-wallet/server/access-token) — Server-side validation. Learn how to validate the access token on your backend.

## Log out users

Upon sign out, the session is invalidated in the database and the client library removes the session stored in the browser.

:::note
When a session is revoked (via logout or an explicit revocation), the session is immediately invalidated in the database. The user is logged out on their next request when the session token is verified.
:::
