Core concepts
Database
Realtime
Functions
Auth
Sessions
How access and refresh tokens work, and how to end sessions safely.
Tokens
Signing in returns a short-lived access token (15 minutes) and a long-lived refresh token (30 days). The SDK refreshes the access token for you.
Reading the session
Signing out
auth.signOut() revokes the refresh token for the current device. Pass { everywhere: true } to end every session for the user.
Rotate on sensitive changes
Revoke all sessions when a user changes their password or email address.
Was this helpful?
© 2026 Tessera, Inc.
Support
Status