What Gets Cleaned Up At Logout: Sessions, Cookies And Tokens
Signing out of IdentityServer removes its authentication cookie. Depending on your setup, other parts of the user’s session may remain afterward, such as a session at an external identity provider or tokens issued to client applications. The table below lists what remains after logout by default, with links to the pages that describe how to remove it.
Artifacts Overview
Section titled “Artifacts Overview”| Artifact | Where It Lives | Default At Logout | How To Clean Up |
|---|---|---|---|
| IdentityServer authentication cookie | Browser, IdentityServer’s cookie handler | Removed when you call SignOutAsync | Removing the authentication cookie |
| Server-side session record | IdentityServer’s session store | Removed automatically when SignOutAsync is called and server-side sessions are enabled | Server-side sessions |
| External identity provider session | The external IdP | Not signed out automatically | External logins |
| Client application sessions/cookies | Each client application | Not cleaned up unless the client is notified | Client notifications |
| Refresh tokens | IdentityServer’s persisted grant store | Kept unless coordination is enabled | Revoking client tokens at logout |
| Reference access tokens | IdentityServer’s persisted grant store | Kept unless coordination is enabled | Revoking client tokens at logout |
| JWT access tokens | The client, self-contained | Never revoked, they expire on their own | Revocation endpoint |
| Consents and other persisted grants | IdentityServer’s persisted grant store | Kept | Session management service, Persisted grant service |
| BFF session and refresh token | The BFF host | Refresh token revoked by default when the BFF logout endpoint is used | BFF logout |
Coordinating Token Lifetime With The User Session
Section titled “Coordinating Token Lifetime With The User Session”Refresh tokens and reference access tokens are not tied to the user’s session at IdentityServer, and stay valid
after logout until they expire. To revoke a client’s tokens when the user’s session ends, set
CoordinateLifetimeWithUserSession on the client configuration,
or enable CoordinateClientLifetimesWithUserSession in
the IdentityServer authentication options. See
Revoking client tokens at logout for
details.
Sessions That End Without An Explicit Logout
Section titled “Sessions That End Without An Explicit Logout”With server-side sessions enabled, a session can also end without the user logging out, for example when it expires or an inactivity timeout is reached.
When a server-side session expires, IdentityServer revokes the refresh tokens and reference access tokens of clients
with a coordinated token lifetime, and sends those clients a back-channel logout notification. Other clients in the
session are only notified when ServerSideSessions.ExpiredSessionsTriggerBackchannelLogout is set to true. This
option defaults to false. See Back-channel logout
for details.
Admin-Initiated Session Termination
Section titled “Admin-Initiated Session Termination”To end a user’s session from your own code, for example from an admin tool, use
ISessionManagementService.RemoveSessionsAsync. Use the SubjectId, SessionId and ClientIds properties of RemoveSessionsContext to select the sessions.
By default, it performs the following steps:
- Removes the server-side session
- Sends back-channel logout notifications
- Revokes refresh tokens and reference access tokens
- Revokes consents
You can turn off each step individually. See Terminating sessions and the Session management service reference.
Client-Side Revocation
Section titled “Client-Side Revocation”A client application can revoke its own refresh tokens and reference access tokens by calling the revocation endpoint, for example when the user logs out of the client. JWT access tokens cannot be revoked and remain valid until they expire, so keep their lifetime short.