Understanding Sessions
A session represents an active login to your QuivaWorks account. Each time you log in from a device or browser, a new session is created.Session Lifetimes
Session Token
24 hoursAuthenticates your browsing and API requests
Refresh Token
7 daysAllows token renewal without logging in again
These lifetimes are fixed. There is no configurable session timeout, no limit on how many sessions you can have open at once, and no device-registration setting.
Viewing Active Sessions
See all devices and locations where you’re currently logged in:- Open Settings from your user menu
- Go to the Sessions tab
- Account — the account name this session is signed in to, shown as the card heading
- Role — the role the session holds
- Location — geographic location, or “unknown” when it can’t be determined
- IP Address — the IP address the session is connecting from
- Device — the device reported by the browser
- Browser — the browser in use
- Expires — when the session ends, shown as a relative time such as “in about 24 hours”
Location shows as “unknown” when geographic data isn’t available for the IP address, or when you’re behind a VPN or proxy.
The Copy token button
Each session card has a Copy token button. It places that session’s live bearer token on your clipboard.Terminating Sessions
Ending a specific session
- Open Settings → Sessions
- Find the session you want to end
- Click Terminate session on that card
Ending all other sessions
Click Terminate sessions at the top of the Sessions tab. This terminates every session except your current one.When to terminate sessions
Suspicious activity
Suspicious activity
Terminate immediately if you see:
- Unfamiliar locations or IP addresses
- Devices you don’t recognise
- Sessions you didn’t create
Forgot to log out
Forgot to log out
Terminate the session if you left yourself logged in on:
- A public or shared computer
- A device you no longer have access to
- A lost, stolen, sold or given-away device
Routine review
Routine review
Review your sessions periodically and terminate any belonging to devices you no longer use.
Password changes and sessions
Changing your password from Settings → Password and authentication terminates every other session and leaves your current one signed in. Resetting your password from the emailed link while signed out terminates every session, including any an attacker is holding. Either way, you receive a confirmation email. See the Authentication guide for the full flow.Admin session management
An admin can force another user to log out of every device.- Open Users in the sidebar — depending on your account it sits at the top level or under More
- Open the dot menu on that user’s row
- Select Logout
- A user reports a lost or stolen device
- You suspect an account is compromised
- Someone is leaving the organisation
- A user forgot to log out on a shared device
Session Security Best Practices
Review regularly
Check your active sessions for unfamiliar devices or locations
Use MFA
Multi-factor authentication protects the login even if your password leaks
Secure your devices
Use device passwords, biometrics and disk encryption on any device with an active session
Log out when done
Especially on shared or public computers — close the session rather than just the browser
Troubleshooting
Session expired unexpectedly
Session expired unexpectedly
Common causes:
- The 24-hour session lifetime elapsed
- An admin used Logout on your account
- You changed or reset your password
- You cleared browser cookies
Can't see location information
Can't see location information
Location relies on geographic data for the IP address, which isn’t always available — VPNs, proxies and corporate networks commonly hide it. This is normal. Use the device and browser fields instead.
Session shows an unexpected device
Session shows an unexpected device
Device and browser are read from the browser’s user agent, which can be generic or altered by remote desktop software, compatibility modes and extensions.If you don’t recognise the session at all, terminate it and change your password.
More sessions than expected
More sessions than expected
Each browser and each device creates its own session, so several is normal.If you genuinely don’t recognise them: click Terminate sessions, change your password, and enable MFA if it isn’t already on.
Next Steps
Authentication
Set up MFA and passkeys
API Keys
Manage programmatic access
Security Overview
Platform and account security
Incident Response
What to do if an account is compromised