◼Still Signed In signed in Open the partner account
paid
Affiliate disclosure. The partner link in the masthead and in the band beside the copy on this page is a sponsored link to a partner operator, and this site may be paid if you open an account through it, at no extra cost to you. It carries rel="sponsored noopener" and opens in a new tab. The subject of this desk is a session - an interval that ends and leaves nothing behind - so its own interest is stated here rather than left for a footer: one link funds the site, and no operator, platform, device, browser or product is named, rated or recommended anywhere on it.
Still Signed In / The endings
Five, not six

The endings: the five ways a session can end

There are five published endings, and the one people believe in most - closing the browser - is not among them. This page collects all five in one place with what each does to the token.

Session spec
published
5
started by you
2
by time
2
closed the tab
0 of 5
the sessionThe interval between signing in and being signed out. It holds your authenticated use of the account and nothing else; the balance, the bets and the limits are held by the account and survive it.
the two clocksThe idle clock runs from your last counted action and restarts; the absolute lifetime runs from the sign-in and never restarts. On the samples 30 minutes and 12 hours, and the earlier one always decides.
the tokenWhat a persistent sign-in leaves on a device, so the next visit needs no password. On the samples 30 days - 1,440 idle windows - and only a sign-out or a revocation removes it.
Direct answer

A session ends when the idle clock fires, when the absolute lifetime arrives, when the account is signed out, when the concurrency limit ends the oldest session, or when the token is revoked by a password change or a device report. Closing the tab is not one of the five, and it removes no token. Of the five, two are started by the reader and two are started by a clock.

All five in one table

Sample F is the list as one invented rules document publishes it, with the one thing a reader most wants to know added to each row.

Sample F - the five published endings and what each leaves behind
EndingStarted byRemoves the tokenControllable
the idle clocka clocknoby acting
the absolute lifetimea clocknono
signing outyouyesyes
the concurrency limitanother sign-innoby not overflowing it
a revocationyou or the operatoryesyes
5 endings2 clocks / 3 people or rules2 of 54 of 5 in some way
sample F - sorting the five by time: idle clock, absolute lifetime → 2 of 5 by an action: signing out, a revocation → 2 of 5 by another sign-in: the concurrency limit → 1 of 5 ending with "closed the tab" in it: 0 of 5 token removed by the ending: signing out and a revocation → 2 of 5 so three of the five leave a persistent sign-in in place.

The consequence of the split

The three endings that leave the token in place are the three that fire without anyone deciding anything, which is why the desk keeps coming back to the same conclusion: the endings that happen to you are not the ones that clear a device. If a session must be gone from a machine - sold, borrowed, repaired, left in a hotel - the ending that matters is the sign-out or a revocation, and nothing that happens on a timer will substitute for it.

The second consequence is about borrowed time. Because the concurrency limit ends the oldest session without warning, a session can end while it looks perfectly alive on another screen, and the reader has no way to tell it apart from the idle clock unless they read the record. That is one of the six beliefs checked on the page that follows this one.

Read next