Skip to content

Authentication sessions

A session records what was actually proven: which credentials, at what time, from which address and user agent. A grant reads a snapshot of it rather than the live session, which is what makes auth_time, acr and amr mean something at the moment the token was issued and not at the moment it is read.

This page will describe opening a session, what a snapshot holds, re-authentication with prompt=login and max_age, and termination.