How to properly revoke refresh tokens when logging out via OAuth in FusionAuth?
-
I'm implementing OAuth logout in a mobile application and noticing that after calling
/oauth2/logoutwith theid_token_hint, the SSO session is properly removed, but the application-level session (refresh token) persists in FusionAuth.When a user signs in with username/password and then logs out via
/oauth2/logout(providing the ID token from/oauth2/tokenasid_token_hint), the SSO session clears successfully, but the refresh token session for the application remains active.What's the correct way to ensure both the SSO session and the refresh token are revoked during logout? Should the refresh token be revoked separately, and if so, what's the recommended flow?
-
The
/oauth2/logoutendpoint only removes the SSO session (the front-channel session controlled by the "Keep Me Signed In" toggle). It does not automatically revoke the refresh token (also known asoffline_access).To properly implement logout, you need to handle both sessions separately:
Recommended Logout Flow
- User initiates logout in your application
- Your backend revokes the refresh token using the Revoke Refresh Tokens API:
Or revoke by user and application:DELETE /api/jwt/refresh/{refreshTokenId}DELETE /api/jwt/refresh?userId={userId}&applicationId={applicationId} - Destroy your local application session (clear tokens, cookies, etc.)
- Redirect to
/oauth2/logoutwithid_token_hintto clear the SSO session
Why This Approach?
Revoking the refresh token from your application (step 2) is better than relying on the logout URL callback because:
- You have direct access to the user's session data
- You know exactly which refresh token to revoke
- You can handle errors gracefully
- The flow is more deterministic
The
/oauth2/logoutendpoint can call a logout URL configured in your FusionAuth OAuth application settings, but handling revocation proactively in your app provides better control.Important Note About JWTs
Since JWTs (access tokens) are stateless, they cannot be immediately revoked by FusionAuth. If you need to invalidate JWTs before their natural expiration, you'll need to implement your own revocation strategy, such as maintaining a token denylist in your application.
Related Documentation
- OAuth Logout API - Details on the
/oauth2/logoutendpoint - Revoke Refresh Tokens API - How to revoke refresh tokens programmatically
- Logout and Session Management - Comprehensive guide on logout strategies and session types
- Revoking JWTs - Strategies for JWT revocation
- JWT Refresh Token Revoke Event - Webhook event when refresh tokens are revoked
-
D dan has marked this topic as solved
-
D dan moved this topic from Staged