<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with session]]></title><description><![CDATA[A list of topics that have been tagged with session]]></description><link>https://fusionauth.io/community/forum/tags/session</link><generator>RSS for Node</generator><lastBuildDate>Thu, 01 Oct 2026 23:21:40 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/session.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[How to revoke all active user sessions and access tokens quickly?]]></title><description><![CDATA[<p dir="auto">To revoke all active user sessions and access tokens immediately during a security incident, you need to take a two-pronged approach: revoking sessions (refresh tokens) and invalidating access tokens.</p>
1. Revoke All Sessions (Refresh Tokens)
<p dir="auto">Sessions in FusionAuth are represented by refresh tokens, and these can be directly revoked using the API:</p>
<p dir="auto"><strong>Revoke all refresh tokens for all users in an application:</strong></p>
DELETE /api/jwt/refresh?applicationId={applicationId}

<p dir="auto"><strong>Revoke all refresh tokens for a specific user:</strong></p>
DELETE /api/jwt/refresh?userId={userId}

<p dir="auto"><strong>Revoke all refresh tokens for a specific user in a specific application:</strong></p>
DELETE /api/jwt/refresh?applicationId={applicationId}&amp;userId={userId}

<p dir="auto">These API calls require an API key with appropriate permissions. When refresh tokens are revoked, users will be unable to obtain new access tokens and will need to re-authenticate.</p>
2. Invalidate Access Tokens via Key Rotation
<p dir="auto">To invalidate access tokens (not just refresh tokens), you need to rotate the JWT signing keys:</p>
<p dir="auto"><strong>In FusionAuth</strong>: Rotate the JWT signing keys used by your tenant/application. This will cause all subsequently validated tokens signed with the old key to fail validation.</p>
<p dir="auto"><strong>In your application server</strong>: Update your application to use the new signing key for validating incoming JWTs. This ensures that tokens signed with the old key are no longer trusted.</p>
<p dir="auto">This approach effectively invalidates all active access tokens because they were signed with the now-rotated key. When your application validates these tokens using the new key, validation will fail and users will need to re-authenticate.</p>
Important Considerations

<strong>Access tokens are stateless JWTs by design</strong>, so they cannot be revoked individually from FusionAuth's side once issued. This is why key rotation is the standard mechanism to invalidate all tokens at once.
<strong>Key rotation is immediate and forceful</strong>: All existing access tokens become invalid immediately upon rotation, making this the appropriate response for security incidents.
<strong>Ensure your application is updated</strong> to accept the new signing key before or immediately after rotation to prevent service disruption for legitimate re-authentication attempts.
<strong>Short access token lifetimes</strong> (minutes, not hours) are strongly recommended as a defense-in-depth measure, since access tokens cannot be individually revoked.
<strong>Use webhooks</strong> to notify your resource servers when refresh tokens are revoked, allowing them to maintain a blocklist of affected users if additional control is needed before access tokens naturally expire.

Alternative: Maintain a Revocation List
<p dir="auto">For access tokens still within their validity period after key rotation, you can implement an application-level revocation mechanism:</p>

Subscribe to the JWT Refresh Token Revoke webhook event
When refresh tokens are revoked, record the affected users/tokens
On each request, check if the user's token has been revoked before processing

<p dir="auto">This provides additional granular control but requires application-level implementation.</p>
Related Documentation

<a href="https://fusionauth.io/docs/apis/jwt/revoke-refresh-tokens" rel="nofollow ugc">Revoke Refresh Tokens API</a> - API for revoking refresh tokens by user, application, or token ID
<a href="https://fusionauth.io/docs/operate/secure/key-rotation" rel="nofollow ugc">Key Rotation</a> - Complete guide to rotating keys in FusionAuth, including JWT signing keys
<a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/jwt/jwt-refresh-token-revoke" rel="nofollow ugc">JWT Refresh Token Revoke Event</a> - Webhook event triggered when refresh tokens are revoked
<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/logout-session-management" rel="nofollow ugc">Logout and Session Management</a> - Overview of session management approaches in FusionAuth
<a href="https://fusionauth.io/community/forum/topic/2207/can-i-revoke-an-access-token-in-fusionauth">Can I Revoke an Access Token?</a> - Community discussion on access token revocation limitations
<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/login-api/json-web-tokens#configuring-jwt-signing" rel="nofollow ugc">Configuring JWT Signing</a> - How to configure JWT signing keys at the tenant and application level

]]></description><link>https://fusionauth.io/community/forum/topic/3161/how-to-revoke-all-active-user-sessions-and-access-tokens-quickly</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3161/how-to-revoke-all-active-user-sessions-and-access-tokens-quickly</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>