Session management
A session includes the data that persists during a period of user inaction with your web application. You can control the session lifetime and what happens when the session expires.
Configure session management
You can configure session management for each brand. If you don't configure session management for a brand, the brand uses the settings from the tenant.
Updates affect only new sessions or sessions that are updated after you save your changes. Updates do not force the expiration of existing sessions that have not been interacted with or updated.
-
Log in to your OneWelcome Identity Platform and select your tenant, if required.
-
On the OneWelcome Identity Platform configuration console, select Core > Session management.
The Session validity period and Maximum session duration are configured globally and are not editable.
The Session validity period controls how long a user's session stays active before expiring if they have not interacted with the system. Each interaction with the system extends the session by this configured amount.
The Maximum session duration controls the maximum amount of time that a user can be logged in for (in minutes). After this time period, the user is forced to log in again.
The Default post logout redirect URL is inherited from the tenant.
-
To add more redirect URLs, select Add more post logout redirect, and enter the URLs in the Other allowed post logout redirect text box.
-
To add brand-specific overrides, in the Brand overrides section, select Add brand.
-
In the Select brand list, select the brand.
-
Enter the Default post logout redirect URL.
-
To add another redirect URL, select Add more post logout redirect, and enter the URLs in the Other allowed post logout redirect text box.
-
-
Add more brands as needed.
-
Select Save.