Configure›Sessions
Sessions
Control how long a signed-in member stays authenticated, and what the issued session token carries with it.
Multi-session handling
Let one browser hold several signed-in members at once and switch between them without a fresh sign-in.
Inactivity — 14 days
Maximum lifetime 2 years
Session token claims
Attach custom claims to every token Harborlock issues so your API can authorize without a second round trip.
Revoke on password change
End every other active session when a member updates their password from the account portal.