Skip to content

What Gets Cleaned Up At Logout: Sessions, Cookies And Tokens

Signing out of IdentityServer removes its authentication cookie. Depending on your setup, other parts of the user’s session may remain afterward, such as a session at an external identity provider or tokens issued to client applications. The table below lists what remains after logout by default, with links to the pages that describe how to remove it.

ArtifactWhere It LivesDefault At LogoutHow To Clean Up
IdentityServer authentication cookieBrowser, IdentityServer’s cookie handlerRemoved when you call SignOutAsyncRemoving the authentication cookie
Server-side session recordIdentityServer’s session storeRemoved automatically when SignOutAsync is called and server-side sessions are enabledServer-side sessions
External identity provider sessionThe external IdPNot signed out automaticallyExternal logins
Client application sessions/cookiesEach client applicationNot cleaned up unless the client is notifiedClient notifications
Refresh tokensIdentityServer’s persisted grant storeKept unless coordination is enabledRevoking client tokens at logout
Reference access tokensIdentityServer’s persisted grant storeKept unless coordination is enabledRevoking client tokens at logout
JWT access tokensThe client, self-containedNever revoked, they expire on their ownRevocation endpoint
Consents and other persisted grantsIdentityServer’s persisted grant storeKeptSession management service, Persisted grant service
BFF session and refresh tokenThe BFF hostRefresh token revoked by default when the BFF logout endpoint is usedBFF logout

Coordinating Token Lifetime With The User Session

Section titled “Coordinating Token Lifetime With The User Session”

Refresh tokens and reference access tokens are not tied to the user’s session at IdentityServer, and stay valid after logout until they expire. To revoke a client’s tokens when the user’s session ends, set CoordinateLifetimeWithUserSession on the client configuration, or enable CoordinateClientLifetimesWithUserSession in the IdentityServer authentication options. See Revoking client tokens at logout for details.

Sessions That End Without An Explicit Logout

Section titled “Sessions That End Without An Explicit Logout”

With server-side sessions enabled, a session can also end without the user logging out, for example when it expires or an inactivity timeout is reached.

When a server-side session expires, IdentityServer revokes the refresh tokens and reference access tokens of clients with a coordinated token lifetime, and sends those clients a back-channel logout notification. Other clients in the session are only notified when ServerSideSessions.ExpiredSessionsTriggerBackchannelLogout is set to true. This option defaults to false. See Back-channel logout for details.

To end a user’s session from your own code, for example from an admin tool, use ISessionManagementService.RemoveSessionsAsync. Use the SubjectId, SessionId and ClientIds properties of RemoveSessionsContext to select the sessions. By default, it performs the following steps:

  • Removes the server-side session
  • Sends back-channel logout notifications
  • Revokes refresh tokens and reference access tokens
  • Revokes consents

You can turn off each step individually. See Terminating sessions and the Session management service reference.

A client application can revoke its own refresh tokens and reference access tokens by calling the revocation endpoint, for example when the user logs out of the client. JWT access tokens cannot be revoked and remain valid until they expire, so keep their lifetime short.