Manage Sessions
Keycloak maintains user sessions to track authenticated users across applications. This guide covers viewing, configuring, and managing user sessions.
TOC
View Active SessionsRealm SessionsPer-User SessionsPer-Client SessionsTerminate SessionsLog Out a Single UserLog Out All Users in a RealmRevocation PolicySession Timeout ConfigurationSSO Session TimeoutsClient Session TimeoutsToken TimeoutsOffline SessionsConfigure Offline SessionsGrant Offline AccessRemember MeEnable Remember MeView Active Sessions
Realm Sessions
- In the Admin Console, go to Sessions.
- The overview shows the total number of active sessions and a breakdown by client.
Per-User Sessions
- Go to Users and select a user.
- Click the Sessions tab.
- View all active sessions for that user, including:
- Session start time
- Last access time
- IP address
- Clients accessed within the session
Per-Client Sessions
- Go to Clients and select a client.
- Click the Sessions tab.
- View all active sessions for that client.
Terminate Sessions
Log Out a Single User
- Go to Users > select the user > Sessions tab.
- Click Sign out on a specific session, or Sign out all sessions to terminate all sessions for that user.
Log Out All Users in a Realm
- Go to Sessions.
- Click Sign out all active sessions.
Signing out all sessions forces every user in the Realm to re-authenticate on their next request. Use this only during security incidents or planned maintenance.
Revocation Policy
A revocation policy invalidates all tokens issued before a specific time:
- Go to Sessions > Revocation.
- Click Set to now or specify a custom Not Before date/time.
- Click Push.
- All tokens issued before the specified time are considered invalid.
Session Timeout Configuration
Configure session timeouts in Realm Settings > Sessions tab.
SSO Session Timeouts
Client Session Timeouts
Token Timeouts
Offline Sessions
Offline sessions allow applications to maintain long-lived refresh tokens that persist beyond the normal SSO session lifetime. This is used for applications that need to perform background operations on behalf of the user.
Configure Offline Sessions
- Go to Realm Settings > Sessions tab.
- Configure:
Grant Offline Access
For a client to request offline tokens:
- Include the
offline_accessscope in the authorization request. - The client must have the
offline_accessscope assigned (either as default or optional). - The user must have the
offline_accessrole (included by default in theoffline_accessscope).
Remember Me
The Remember Me feature allows users to extend their session duration by checking a "Remember Me" box on the login page.
Enable Remember Me
- Go to Realm Settings > Login tab.
- Enable Remember me.
- Configure the "Remember Me" session timeouts in the Sessions tab (SSO Session Idle Remember Me, SSO Session Max Remember Me).