Skip to main content
Monitor and control your active login sessions across all devices to maintain account security.

Understanding Sessions

A session represents an active login to your QuivaWorks account. Each time you log in from a device or browser, a new session is created.

Session Lifetimes

Session Token

24 hoursAuthenticates your browsing and API requests

Refresh Token

7 daysAllows token renewal without logging in again
These lifetimes are fixed. There is no configurable session timeout, no limit on how many sessions you can have open at once, and no device-registration setting.

Viewing Active Sessions

See all devices and locations where you’re currently logged in:
  1. Open Settings from your user menu
  2. Go to the Sessions tab
Each session appears as a card showing:
  • Account — the account name this session is signed in to, shown as the card heading
  • Role — the role the session holds
  • Location — geographic location, or “unknown” when it can’t be determined
  • IP Address — the IP address the session is connecting from
  • Device — the device reported by the browser
  • Browser — the browser in use
  • Expires — when the session ends, shown as a relative time such as “in about 24 hours”
Your current session is marked with a green Your session pill.
Location shows as “unknown” when geographic data isn’t available for the IP address, or when you’re behind a VPN or proxy.

The Copy token button

Each session card has a Copy token button. It places that session’s live bearer token on your clipboard.
A copied session token authenticates as you, with your role, until the session expires or is terminated. Treat it exactly like a password: never paste it into a chat message, a ticket, a log file, or source control. If you have pasted one somewhere it doesn’t belong, terminate that session — see below.

Terminating Sessions

Ending a specific session

  1. Open Settings → Sessions
  2. Find the session you want to end
  3. Click Terminate session on that card
Use this if you left yourself logged in on a shared computer, or no longer use a particular device.

Ending all other sessions

Click Terminate sessions at the top of the Sessions tab. This terminates every session except your current one.
You’ll be logged out on all other devices immediately and will need to log in again on each of them.

When to terminate sessions

Terminate immediately if you see:
  • Unfamiliar locations or IP addresses
  • Devices you don’t recognise
  • Sessions you didn’t create
After terminating them, change your password and review the incident response steps.
Terminate the session if you left yourself logged in on:
  • A public or shared computer
  • A device you no longer have access to
  • A lost, stolen, sold or given-away device
If a token from Copy token ended up somewhere it shouldn’t have, terminating that session invalidates it.
Review your sessions periodically and terminate any belonging to devices you no longer use.

Password changes and sessions

Changing your password from Settings → Password and authentication terminates every other session and leaves your current one signed in. Resetting your password from the emailed link while signed out terminates every session, including any an attacker is holding. Either way, you receive a confirmation email. See the Authentication guide for the full flow.

Admin session management

An admin can force another user to log out of every device.
  1. Open Users in the sidebar — depending on your account it sits at the top level or under More
  2. Open the dot menu on that user’s row
  3. Select Logout
This immediately terminates all of that user’s sessions. They will need to log in again.
Suspend does not end live sessions. Suspending a user blocks future sign-ins, but any session they already hold keeps working until it expires. When you are removing someone’s access urgently, use Logout as well as Suspend.
When to use Logout:
  • A user reports a lost or stolen device
  • You suspect an account is compromised
  • Someone is leaving the organisation
  • A user forgot to log out on a shared device

Session Security Best Practices

Review regularly

Check your active sessions for unfamiliar devices or locations

Use MFA

Multi-factor authentication protects the login even if your password leaks

Secure your devices

Use device passwords, biometrics and disk encryption on any device with an active session

Log out when done

Especially on shared or public computers — close the session rather than just the browser

Troubleshooting

Common causes:
  • The 24-hour session lifetime elapsed
  • An admin used Logout on your account
  • You changed or reset your password
  • You cleared browser cookies
Solution: log in again. This is normal behaviour.
Location relies on geographic data for the IP address, which isn’t always available — VPNs, proxies and corporate networks commonly hide it. This is normal. Use the device and browser fields instead.
Device and browser are read from the browser’s user agent, which can be generic or altered by remote desktop software, compatibility modes and extensions.If you don’t recognise the session at all, terminate it and change your password.
Each browser and each device creates its own session, so several is normal.If you genuinely don’t recognise them: click Terminate sessions, change your password, and enable MFA if it isn’t already on.

Next Steps

Authentication

Set up MFA and passkeys

API Keys

Manage programmatic access

Security Overview

Platform and account security

Incident Response

What to do if an account is compromised