> For the complete documentation index, see [llms.txt](https://ztrust.gitbook.io/ztrust-documentation/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://ztrust.gitbook.io/ztrust-documentation/user-manual-ztrust-v2.0/guide-to-navigation/sessions.md).

# Sessions

<figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2Fshi8YCC19dlRbWgb3vDx%2Fimage.png?alt=media&amp;token=8ea0919a-5720-42d2-844e-8d15ba222f6b" alt=""><figcaption></figcaption></figure>

When a user logs into realms, ZTrust keeps a user session active for each individual and remembers every client visited by that user within the session.

<figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FnP0fx2RWJW4GFLU2iK3B%2F39.png?alt=media&amp;token=d76ec175-9141-475b-bdac-6e62e57a0ac8" alt=""><figcaption></figcaption></figure>

#### **Action**

This includes actions that can be performed on user sessions, such as revocation and signing out all active sessions.

After clicking on Revocation, you will get the below screen.

<figure><img src="https://1778922777-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F3EUK5AUZv0UVaI5S0CTM%2Fuploads%2FuNL0GPfbVYN4eAzSVVL0%2F40.png?alt=media&amp;token=ecfeb582-3875-45d7-9446-04bba873c839" alt=""><figcaption></figcaption></figure>

In case of a system breach, you have the ability to invalidate all user sessions and access tokens.&#x20;

It serves as a method to revoke all currently active sessions and access tokens.&#x20;

The Not Before feature allows you to revoke any tokens issued before a specified date and time.

#### **Set to now**

If you want to set the policy with the current time and date, click on Set to now.

#### **Clear**

To remove the set time and date, click on Clear to delete it.

#### **Push**

If you want to push this revocation policy to any registered OIDC Client using the ZTrust Client Adapter, click on Push.

#### **Cancel**

If you decide not to proceed with any action on the user session after making the above changes, click on Cancel.

#### **Sign out all active sessions**

Clicking on Sign out all active sessions will sign out all users within the realm, invalidating all Single Sign-On (SSO) cookies.&#x20;

ZTrust notifies clients about the logout event through the OIDC client adapter.

<br>
