<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to revoke all active user sessions and access tokens quickly?]]></title><description><![CDATA[<p dir="auto">We need to immediately revoke all active user sessions and access tokens across our application due to a security incident. What is the recommended approach to achieve this in FusionAuth?</p>
<p dir="auto">We understand that refresh tokens can be revoked, but we specifically need to invalidate access tokens that are already issued and in use.</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3161/how-to-revoke-all-active-user-sessions-and-access-tokens-quickly</link><generator>RSS for Node</generator><lastBuildDate>Thu, 01 Oct 2026 23:21:38 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3161.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 28 Sep 2026 20:41:11 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to revoke all active user sessions and access tokens quickly? on Mon, 28 Sep 2026 20:41:22 GMT]]></title><description><![CDATA[<p dir="auto">To revoke all active user sessions and access tokens immediately during a security incident, you need to take a two-pronged approach: revoking sessions (refresh tokens) and invalidating access tokens.</p>
<h2>1. Revoke All Sessions (Refresh Tokens)</h2>
<p dir="auto">Sessions in FusionAuth are represented by refresh tokens, and these can be directly revoked using the API:</p>
<p dir="auto"><strong>Revoke all refresh tokens for all users in an application:</strong></p>
<pre><code>DELETE /api/jwt/refresh?applicationId={applicationId}
</code></pre>
<p dir="auto"><strong>Revoke all refresh tokens for a specific user:</strong></p>
<pre><code>DELETE /api/jwt/refresh?userId={userId}
</code></pre>
<p dir="auto"><strong>Revoke all refresh tokens for a specific user in a specific application:</strong></p>
<pre><code>DELETE /api/jwt/refresh?applicationId={applicationId}&amp;userId={userId}
</code></pre>
<p dir="auto">These API calls require an API key with appropriate permissions. When refresh tokens are revoked, users will be unable to obtain new access tokens and will need to re-authenticate.</p>
<h2>2. Invalidate Access Tokens via Key Rotation</h2>
<p dir="auto">To invalidate access tokens (not just refresh tokens), you need to rotate the JWT signing keys:</p>
<p dir="auto"><strong>In FusionAuth</strong>: Rotate the JWT signing keys used by your tenant/application. This will cause all subsequently validated tokens signed with the old key to fail validation.</p>
<p dir="auto"><strong>In your application server</strong>: Update your application to use the new signing key for validating incoming JWTs. This ensures that tokens signed with the old key are no longer trusted.</p>
<p dir="auto">This approach effectively invalidates all active access tokens because they were signed with the now-rotated key. When your application validates these tokens using the new key, validation will fail and users will need to re-authenticate.</p>
<h2>Important Considerations</h2>
<ul>
<li><strong>Access tokens are stateless JWTs by design</strong>, so they cannot be revoked individually from FusionAuth's side once issued. This is why key rotation is the standard mechanism to invalidate all tokens at once.</li>
<li><strong>Key rotation is immediate and forceful</strong>: All existing access tokens become invalid immediately upon rotation, making this the appropriate response for security incidents.</li>
<li><strong>Ensure your application is updated</strong> to accept the new signing key before or immediately after rotation to prevent service disruption for legitimate re-authentication attempts.</li>
<li><strong>Short access token lifetimes</strong> (minutes, not hours) are strongly recommended as a defense-in-depth measure, since access tokens cannot be individually revoked.</li>
<li><strong>Use webhooks</strong> to notify your resource servers when refresh tokens are revoked, allowing them to maintain a blocklist of affected users if additional control is needed before access tokens naturally expire.</li>
</ul>
<h2>Alternative: Maintain a Revocation List</h2>
<p dir="auto">For access tokens still within their validity period after key rotation, you can implement an application-level revocation mechanism:</p>
<ol>
<li>Subscribe to the JWT Refresh Token Revoke webhook event</li>
<li>When refresh tokens are revoked, record the affected users/tokens</li>
<li>On each request, check if the user's token has been revoked before processing</li>
</ol>
<p dir="auto">This provides additional granular control but requires application-level implementation.</p>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/apis/jwt/revoke-refresh-tokens" rel="nofollow ugc">Revoke Refresh Tokens API</a> - API for revoking refresh tokens by user, application, or token ID</li>
<li><a href="https://fusionauth.io/docs/operate/secure/key-rotation" rel="nofollow ugc">Key Rotation</a> - Complete guide to rotating keys in FusionAuth, including JWT signing keys</li>
<li><a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/jwt/jwt-refresh-token-revoke" rel="nofollow ugc">JWT Refresh Token Revoke Event</a> - Webhook event triggered when refresh tokens are revoked</li>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/logout-session-management" rel="nofollow ugc">Logout and Session Management</a> - Overview of session management approaches in FusionAuth</li>
<li><a href="https://fusionauth.io/community/forum/topic/2207/can-i-revoke-an-access-token-in-fusionauth">Can I Revoke an Access Token?</a> - Community discussion on access token revocation limitations</li>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/login-api/json-web-tokens#configuring-jwt-signing" rel="nofollow ugc">Configuring JWT Signing</a> - How to configure JWT signing keys at the tenant and application level</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8660</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8660</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Mon, 28 Sep 2026 20:41:22 GMT</pubDate></item></channel></rss>