New
Use Revoke sessions to sign a user out of every browser and device at once,
for example after a lost laptop or a suspected account takeover. You need
write-tier Platform Admin access and a reason for the action.
- Open Users and click the user’s row.
- Check the count under Active sessions.
- In Actions, select Revoke sessions.
- Verify the email address, enter your reason, and select Revoke sessions.
After confirmation, the Active sessions count drops to 0 and the user has to
sign in again everywhere. A browser tab that is already open can keep working
for up to five minutes before it signs out too. If there is nothing to revoke,
you see “No active sessions to revoke.”
This action does not change the password, remove a ban, disconnect MCP clients,
or revoke API keys. To also stop a compromised password from working, send a
password reset.
The user’s audit log records user.force_logout, the staff actor, your reason,
and the number of sessions revoked. The saved record also includes the
associated account when one exists. If the action fails, the sessions stay
active; your reason remains in the dialog so you can retry. Last modified on September 12, 2026