Security

Sessions, refresh and the 15-minute token: security you never see

May 28, 2026 · Jogajog team · 2 min read

Quick answer: Access tokens live fifteen minutes; sessions renew silently through rotating refresh tokens for up to thirty days of use. Stolen tokens age out fast, refresh reuse is detected, and members experience none of it — just an app that stays signed in.

How it works

Rotation means a copied refresh token betrays itself on second use.

Suspension and removal cut new tokens immediately; short access life bounds the tail.

Sign-out on shared devices revokes the session server-side.

Frequently asked questions

Why thirty days?

Long enough that phones feel permanently signed in, short enough that lost devices age out.

Can admins force-expire a member's sessions?

Trashing or suspending the member does exactly that.

See it with your own data — request a free branded demo →

← All articles

See this feature with your own data.

Free branded demo, built from your spreadsheet, this week.

Get your free demo