<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[How to properly revoke refresh tokens when logging out via OAuth in FusionAuth?]]></title><description><![CDATA[<p dir="auto">I'm implementing OAuth logout in a mobile application and noticing that after calling <code>/oauth2/logout</code> with the <code>id_token_hint</code>, the SSO session is properly removed, but the application-level session (refresh token) persists in FusionAuth.</p>
<p dir="auto">When a user signs in with username/password and then logs out via <code>/oauth2/logout</code> (providing the ID token from <code>/oauth2/token</code> as <code>id_token_hint</code>), the SSO session clears successfully, but the refresh token session for the application remains active.</p>
<p dir="auto">What's the correct way to ensure both the SSO session and the refresh token are revoked during logout? Should the refresh token be revoked separately, and if so, what's the recommended flow?</p>
]]></description><link>https://fusionauth.io/community/forum/topic/3192/how-to-properly-revoke-refresh-tokens-when-logging-out-via-oauth-in-fusionauth</link><generator>RSS for Node</generator><lastBuildDate>Fri, 09 Oct 2026 03:10:43 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/topic/3192.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 02 Oct 2026 23:41:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to How to properly revoke refresh tokens when logging out via OAuth in FusionAuth? on Fri, 02 Oct 2026 23:41:12 GMT]]></title><description><![CDATA[<p dir="auto">The <code>/oauth2/logout</code> endpoint only removes the <strong>SSO session</strong> (the front-channel session controlled by the "Keep Me Signed In" toggle). It does <strong>not</strong> automatically revoke the <strong>refresh token</strong> (also known as <code>offline_access</code>).</p>
<p dir="auto">To properly implement logout, you need to handle both sessions separately:</p>
<h2>Recommended Logout Flow</h2>
<ol>
<li><strong>User initiates logout</strong> in your application</li>
<li><strong>Your backend revokes the refresh token</strong> using the <a href="https://fusionauth.io/docs/apis/jwt/revoke-refresh-tokens" rel="nofollow ugc">Revoke Refresh Tokens API</a>:<pre><code>DELETE /api/jwt/refresh/{refreshTokenId}
</code></pre>
Or revoke by user and application:<pre><code>DELETE /api/jwt/refresh?userId={userId}&amp;applicationId={applicationId}
</code></pre>
</li>
<li><strong>Destroy your local application session</strong> (clear tokens, cookies, etc.)</li>
<li><strong>Redirect to <code>/oauth2/logout</code></strong> with <code>id_token_hint</code> to clear the SSO session</li>
</ol>
<h2>Why This Approach?</h2>
<p dir="auto">Revoking the refresh token from your application (step 2) is better than relying on the logout URL callback because:</p>
<ul>
<li>You have direct access to the user's session data</li>
<li>You know exactly which refresh token to revoke</li>
<li>You can handle errors gracefully</li>
<li>The flow is more deterministic</li>
</ul>
<p dir="auto">The <code>/oauth2/logout</code> endpoint can call a logout URL configured in your FusionAuth OAuth application settings, but handling revocation proactively in your app provides better control.</p>
<h2>Important Note About JWTs</h2>
<p dir="auto">Since JWTs (access tokens) are stateless, they cannot be immediately revoked by FusionAuth. If you need to invalidate JWTs before their natural expiration, you'll need to implement your own revocation strategy, such as maintaining a token denylist in your application.</p>
<h2>Related Documentation</h2>
<ul>
<li><a href="https://fusionauth.io/docs/apis/oauth/logout" rel="nofollow ugc">OAuth Logout API</a> - Details on the <code>/oauth2/logout</code> endpoint</li>
<li><a href="https://fusionauth.io/docs/apis/jwt/revoke-refresh-tokens" rel="nofollow ugc">Revoke Refresh Tokens API</a> - How to revoke refresh tokens programmatically</li>
<li><a href="https://fusionauth.io/docs/lifecycle/authenticate-users/logout-session-management" rel="nofollow ugc">Logout and Session Management</a> - Comprehensive guide on logout strategies and session types</li>
<li><a href="https://fusionauth.io/articles/tokens/revoking-jwts" rel="nofollow ugc">Revoking JWTs</a> - Strategies for JWT revocation</li>
<li><a href="https://fusionauth.io/docs/extend/events-and-webhooks/events/jwt/jwt-refresh-token-revoke" rel="nofollow ugc">JWT Refresh Token Revoke Event</a> - Webhook event when refresh tokens are revoked</li>
</ul>
]]></description><link>https://fusionauth.io/community/forum/post/8721</link><guid isPermaLink="true">https://fusionauth.io/community/forum/post/8721</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Fri, 02 Oct 2026 23:41:12 GMT</pubDate></item></channel></rss>