To revoke all active user sessions and access tokens immediately during a security incident, you need to take a two-pronged approach: revoking sessions (refresh tokens) and invalidating access tokens.
1. Revoke All Sessions (Refresh Tokens)Sessions in FusionAuth are represented by refresh tokens, and these can be directly revoked using the API:
Revoke all refresh tokens for all users in an application:
DELETE /api/jwt/refresh?applicationId={applicationId}Revoke all refresh tokens for a specific user:
DELETE /api/jwt/refresh?userId={userId}Revoke all refresh tokens for a specific user in a specific application:
DELETE /api/jwt/refresh?applicationId={applicationId}&userId={userId}These API calls require an API key with appropriate permissions. When refresh tokens are revoked, users will be unable to obtain new access tokens and will need to re-authenticate.
2. Invalidate Access Tokens via Key RotationTo invalidate access tokens (not just refresh tokens), you need to rotate the JWT signing keys:
In FusionAuth: Rotate the JWT signing keys used by your tenant/application. This will cause all subsequently validated tokens signed with the old key to fail validation.
In your application server: Update your application to use the new signing key for validating incoming JWTs. This ensures that tokens signed with the old key are no longer trusted.
This approach effectively invalidates all active access tokens because they were signed with the now-rotated key. When your application validates these tokens using the new key, validation will fail and users will need to re-authenticate.
Important Considerations Access tokens are stateless JWTs by design, so they cannot be revoked individually from FusionAuth's side once issued. This is why key rotation is the standard mechanism to invalidate all tokens at once. Key rotation is immediate and forceful: All existing access tokens become invalid immediately upon rotation, making this the appropriate response for security incidents. Ensure your application is updated to accept the new signing key before or immediately after rotation to prevent service disruption for legitimate re-authentication attempts. Short access token lifetimes (minutes, not hours) are strongly recommended as a defense-in-depth measure, since access tokens cannot be individually revoked. Use webhooks to notify your resource servers when refresh tokens are revoked, allowing them to maintain a blocklist of affected users if additional control is needed before access tokens naturally expire. Alternative: Maintain a Revocation ListFor access tokens still within their validity period after key rotation, you can implement an application-level revocation mechanism:
Subscribe to the JWT Refresh Token Revoke webhook event When refresh tokens are revoked, record the affected users/tokens On each request, check if the user's token has been revoked before processingThis provides additional granular control but requires application-level implementation.
Related Documentation Revoke Refresh Tokens API - API for revoking refresh tokens by user, application, or token ID Key Rotation - Complete guide to rotating keys in FusionAuth, including JWT signing keys JWT Refresh Token Revoke Event - Webhook event triggered when refresh tokens are revoked Logout and Session Management - Overview of session management approaches in FusionAuth Can I Revoke an Access Token? - Community discussion on access token revocation limitations Configuring JWT Signing - How to configure JWT signing keys at the tenant and application level