The endings: the five ways a session can end
There are five published endings, and the one people believe in most - closing the browser - is not among them. This page collects all five in one place with what each does to the token.
- published
- 5
- started by you
- 2
- by time
- 2
- closed the tab
- 0 of 5
A session ends when the idle clock fires, when the absolute lifetime arrives, when the account is signed out, when the concurrency limit ends the oldest session, or when the token is revoked by a password change or a device report. Closing the tab is not one of the five, and it removes no token. Of the five, two are started by the reader and two are started by a clock.
All five in one table
Sample F is the list as one invented rules document publishes it, with the one thing a reader most wants to know added to each row.
| Ending | Started by | Removes the token | Controllable |
|---|---|---|---|
| the idle clock | a clock | no | by acting |
| the absolute lifetime | a clock | no | no |
| signing out | you | yes | yes |
| the concurrency limit | another sign-in | no | by not overflowing it |
| a revocation | you or the operator | yes | yes |
| 5 endings | 2 clocks / 3 people or rules | 2 of 5 | 4 of 5 in some way |
The consequence of the split
The three endings that leave the token in place are the three that fire without anyone deciding anything, which is why the desk keeps coming back to the same conclusion: the endings that happen to you are not the ones that clear a device. If a session must be gone from a machine - sold, borrowed, repaired, left in a hotel - the ending that matters is the sign-out or a revocation, and nothing that happens on a timer will substitute for it.
The second consequence is about borrowed time. Because the concurrency limit ends the oldest session without warning, a session can end while it looks perfectly alive on another screen, and the reader has no way to tell it apart from the idle clock unless they read the record. That is one of the six beliefs checked on the page that follows this one.
- Learn which of the five endings your account publishes, and which two remove the token.
- Use the two controllable endings deliberately: sign out, and revoke when a device is gone.
- Do not count a closed browser or a closed app as an ending; on the samples it is 0 of 5.
- Expect the concurrency limit to end a session elsewhere with no warning on the screen that loses it.
- Where a session must be gone, verify it in the record rather than assuming a timer did it.