Skip to main content

Sessions

Sessions

Last verified: 2026-07-09.

The Sessions panel on your Account Security page shows everywhere your account is currently signed in, so you can spot anything unexpected and sign it out. Each row is one active session — for example, your phone, your laptop, or a browser you used once and forgot to log out of.

Where you're logged in

Every active session shows a few details to help you recognise it:

  • The device — a short description of the browser or device, when available.
  • The approximate location, based on the IP address. Location is always labelled based on IP — IP-based geolocation is not exact, so treat it as a rough guide, not a pinpoint.
  • Private or local addresses are labelled Local or private network instead of being presented as a failed foreign-location lookup. Public addresses that cannot be resolved show a masked-IP fallback and Location unavailable copy.
  • The last active time, so you can tell a session you used a minute ago from one that has been idle for days.

"This device" and the "2FA-verified" badge

Two labels make the list easier to read at a glance:

  • This device marks the session you are using right now. It is the one you do not want to sign out by accident.
  • 2FA-verified appears on any session that completed two-factor authentication when it signed in. It is a reassurance that the sign-in passed your second step, not just the password.

Signing out a single session

If you see a session you don't recognise, or one on a device you no longer use, choose Sign out on that row. That session is ended immediately and will need to sign in again from scratch. The other sessions are left alone.

Sign out everywhere else

When you want a clean slate — after using a shared computer, or if you are worried someone else has access — choose Sign out everywhere else. This ends every session except the one you are using now.

Your current session is protected from accidental sign-out. "Sign out everywhere else" never logs you out of the device you are on, so you won't lock yourself out by tidying up. To end your current session, simply log out the normal way.

Your session token is never shown

Awthy never shows or exposes your actual session token — the secret value that keeps you logged in. The panel only displays a description of each session, never the token itself, so nothing on this page can be copied to hijack a login.

As with every part of Awthy, the plugin will never ask for your password or a one-time code, and never sends them by email. If a message claiming to be from Awthy asks for your credentials, treat it as phishing.