FusionAuth
    • Home
    • Categories
    • Recent
    • Popular
    • Pricing
    • Contact us
    • Docs
    • Login

    How to properly revoke refresh tokens when logging out via OAuth in FusionAuth?

    Scheduled Pinned Locked Moved Solved
    Frequently Asked Questions (FAQ)
    oauth logout refresh-token sso session
    1
    2
    26
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • F
      FASupportBot
      last edited by

      I'm implementing OAuth logout in a mobile application and noticing that after calling /oauth2/logout with the id_token_hint, the SSO session is properly removed, but the application-level session (refresh token) persists in FusionAuth.

      When a user signs in with username/password and then logs out via /oauth2/logout (providing the ID token from /oauth2/token as id_token_hint), the SSO session clears successfully, but the refresh token session for the application remains active.

      What's the correct way to ensure both the SSO session and the refresh token are revoked during logout? Should the refresh token be revoked separately, and if so, what's the recommended flow?

      If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

      1 Reply Last reply Reply Quote 0
      • F
        FASupportBot
        last edited by

        The /oauth2/logout endpoint only removes the SSO session (the front-channel session controlled by the "Keep Me Signed In" toggle). It does not automatically revoke the refresh token (also known as offline_access).

        To properly implement logout, you need to handle both sessions separately:

        Recommended Logout Flow

        1. User initiates logout in your application
        2. Your backend revokes the refresh token using the Revoke Refresh Tokens API:
          DELETE /api/jwt/refresh/{refreshTokenId}
          
          Or revoke by user and application:
          DELETE /api/jwt/refresh?userId={userId}&applicationId={applicationId}
          
        3. Destroy your local application session (clear tokens, cookies, etc.)
        4. Redirect to /oauth2/logout with id_token_hint to clear the SSO session

        Why This Approach?

        Revoking the refresh token from your application (step 2) is better than relying on the logout URL callback because:

        • You have direct access to the user's session data
        • You know exactly which refresh token to revoke
        • You can handle errors gracefully
        • The flow is more deterministic

        The /oauth2/logout endpoint can call a logout URL configured in your FusionAuth OAuth application settings, but handling revocation proactively in your app provides better control.

        Important Note About JWTs

        Since JWTs (access tokens) are stateless, they cannot be immediately revoked by FusionAuth. If you need to invalidate JWTs before their natural expiration, you'll need to implement your own revocation strategy, such as maintaining a token denylist in your application.

        Related Documentation

        • OAuth Logout API - Details on the /oauth2/logout endpoint
        • Revoke Refresh Tokens API - How to revoke refresh tokens programmatically
        • Logout and Session Management - Comprehensive guide on logout strategies and session types
        • Revoking JWTs - Strategies for JWT revocation
        • JWT Refresh Token Revoke Event - Webhook event when refresh tokens are revoked

        If you are looking for professional support and not just bot-provided support, please check out https://fusionauth.io/pricing and pick a plan that fits your needs.

        1 Reply Last reply Reply Quote 0
        • danD dan has marked this topic as solved
        • danD dan moved this topic from Staged
        • First post
          Last post