Sessions and devices

How long a sign-in lasts, and how to see and end it from any device.

How long a session lasts

A session lasts up to 30 days, refreshed automatically at most once a day while you're active. If a browser goes genuinely untouched for 30 days, that session expires on its own: you don't need to do anything.

Viewing your sessions

Dashboard → Settings → Security → Sessions and devices lists every device currently signed in, with its approximate location (IP address) and when it was last active. The device you're using right now is marked.

Signing out one device, or everywhere else

  • "Sign out" next to any OTHER device ends that session immediately, it's invalidated server-side, not just told to forget the cookie.
  • "Sign out all other devices" ends every session except the one you're using right now.
  • Changing your password automatically signs out every other session, as a safety measure.

Step-up re-authentication

A handful of sensitive actions ask you to re-confirm your password or a two-factor code first, if it's been more than 10 minutes since you last did: creating or revoking an API key, rotating a webhook secret, turning off two-factor authentication or removing a passkey, changing your email or password, deleting your account or organization, exporting your data, changing billing, and connecting a bank account. This is separate from your session's own 30-day lifetime: it protects against someone using a device you left signed in and unlocked.

Security activity

Dashboard → Settings → Security → Security activity lists your own sign-ins, password and two-factor changes, passkey changes, data exports, share-link creation and revocation, and account deletion requests, newest first, in plain English. It only ever shows your own actions, never a teammate's, even in the same organization. An organization's owner or admin has a separate, broader audit log for the whole team on the Team page.

New-device notice

The first time your account signs in from a browser it hasn't seen before, you get an email with the time, IP address, and device. If that wasn't you, sign in and review your sessions and password right away.

Cookies

The dashboard sets exactly one cookie to keep you signed in (__Host-arkrel_session in production): HttpOnly (page scripts can't read it), Secure, and SameSite=Lax. It is never used for advertising or cross-site tracking.