# Auto logout when sesion time outs

**URL:** <https://forum.keycloak.org/t/auto-logout-when-sesion-time-outs/26609>\
**Category:** Securing applications\
**Created:** [June 21, 2024, 4:48am UTC](https://forum.keycloak.org/t/auto-logout-when-sesion-time-outs/26609 "2024-06-21T04:48:59Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmr](https://avatars.discourse-cdn.com/v4/letter/j/d6d6ee/32.png) [@jmr](https://forum.keycloak.org/u/jmr)\
**Post date:** [June 21, 2024, 4:48am UTC](https://forum.keycloak.org/t/auto-logout-when-sesion-time-outs/26609/1 "2024-06-21T04:48:59Z")

</div>

i am using a react application i need to autonatically logout from a session when its time out.  
i am uing keycloak-js package in front end

---

<div class="post-metadata">

**Author:** ![embesozzi](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/embesozzi/32/12390_2.png) [@embesozzi](https://forum.keycloak.org/u/embesozzi)\
**Post date:** [June 22, 2024, 2:11pm UTC](https://forum.keycloak.org/t/auto-logout-when-sesion-time-outs/26609/2 "2024-06-22T14:11:18Z")

</div>

If you are talking about an IdP session, here [1] is a demo app that follows OpenID Connect Session Management standard [2], which will provide some references. Nevertheless, the upcoming deprecation of third-party cookies will impact OpenID Connect Session Management, therefore, keep this in mind.  
If you are talking about the app session, it simply triggers the `kc.logout()` method when the session times out.

[1] [GitHub - embesozzi/oidc-check-session-iframe: Simple html page for implementing check session iframe based on OpenID Connect Session Management 1.0](https://github.com/embesozzi/oidc-check-session-iframe)  
[2] [Final: OpenID Connect Session Management 1.0](https://openid.net/specs/openid-connect-session-1_0.html)

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [June 22, 2024, 7:24pm UTC](https://forum.keycloak.org/t/auto-logout-when-sesion-time-outs/26609/3 "2024-06-22T19:24:06Z")

</div>

The `keycloak-js` library offers you some callback methods (which are also using the iframe approach @embesozzi mentioned):

> - **onAuthLogout** - Called if the user is logged out (will only be called if the session status iframe is enabled, or in Cordova mode).
> - **onTokenExpired** - Called when the access token is expired. If a refresh token is available the token can be refreshed with updateToken, or in cases where it is not (that is, with implicit flow) you can redirect to the login screen to obtain a new access token.

👉 [JavaScript Adapter API Reference](https://www.keycloak.org/docs/25.0.0/securing_apps/#api-reference)
