A device is not a session
A device represents the longer-lived security context of a browser or endpoint. A session is the revocable access associated with that device.
One session can therefore be ended, or a complete device and all its sessions removed, without signing out every other endpoint.
Sign-in and security confirmation
Accounts with a registered security key receive no session after the password step alone. The WebAuthn confirmation completes authentication.
Passkeys reduce phishing risk, but do not prove that an endpoint is malware-free or physically controlled by the intended person.
- WebAuthn as an additional possession proof
- Device context remains bound to sign-in
- Removed devices remain revoked
- Failed attempts become security events
Revocation and recovery
Users can review active sessions, end individual sessions, verify devices and remove devices. Administrators can revoke every session belonging to an account when required.
Device revocation, panic mode and the duress path remove related push subscriptions. On the next eligible sign-in path, the client removes account-scoped local security state including history, ratchet state, outbox, prekeys and device identity.
Local cleanup cannot physically erase an endpoint that remains offline or compromised. If deletion is blocked by an open browser context, the interface reports the condition explicitly instead of entering a reload loop.
Public claim boundary
Browser device identity is not hardware attestation. Device verification confirms a controlled relationship between authorised endpoints, not operating-system integrity.
Signing keys remain non-exportable. Exchange keys are preferably persisted as non-exportable CryptoKey objects; iOS/WebKit uses a documented JWK fallback when reliable CryptoKey persistence is unavailable.
