The persistent sign-in: the box you ticked once
The box that says stay signed in does not lengthen the session. It replaces it with something that outlives it, and that difference is measured in weeks rather than minutes.
- idle window
- 30 minutes
- session
- 12 hours
- token
- 30 days
- ratio
- 1,440 times
A persistent sign-in stores a separate token on the device so the next visit creates a session without a password. On the samples the token lasts 30 days against a 30-minute idle window and a 12-hour session. It is the longest-lived credential in the picture, it survives closing the browser, and it is the reason a shared device can still be signed in days later.
Three durations, one account
Sample D puts the three published periods next to each other. Each one is a different object, and only the shortest one is the session.
| Object | Published period | In minutes | Ended by |
|---|---|---|---|
| the idle clock | 30 minutes | 30 | no counted action |
| the session | 12 hours | 720 | the lifetime, or a sign-out |
| the persistent token | 30 days | 43,200 | expiry, a password change, or revocation |
| 3 periods | 48 times the session chain | 43,200 | 3 different ends |
What the box changes, and what it does not
Ticking it does not change the idle clock or the lifetime. Those still run, and a session created by a persistent token still ends on the same schedule as any other; what changes is that the next visit does not need a password and creates a fresh session immediately. The consequence people miss is the one that matters: signing out is normally what removes the token, so a device where the box was ticked and no sign-out ever happened can be reopened into the account after the session and even after the browser was closed. Closing the tab is not a sign-out, which is the subject of its own page in this desk.
The second consequence is that the token is the most valuable thing on the device. A password can be changed and a session expires by itself; a token that is valid for weeks is worth revoking deliberately, and the standard way to do that is a password change or the sign-out-everywhere control named on the devices page.
- Know whether the box is ticked on each device, and treat a tick as a decision with a period attached rather than as a convenience.
- Expect the persistent token to outlive the session by a factor of weeks; on the samples it is 60 sessions.
- Revoke deliberately when a device is lost, resold or borrowed: a password change is the usual way.
- Do not rely on closing the browser to end a persistent sign-in; on the samples it does not.
- Sign out rather than close the tab on any device you share, because signing out is what removes the token.