# Difference between "Client Session" and "SSO Session" in timeout settings?

**URL:** <https://forum.keycloak.org/t/difference-between-client-session-and-sso-session-in-timeout-settings/4190>\
**Category:** Configuring the server\
**Created:** [August 10, 2020, 2:29am UTC](https://forum.keycloak.org/t/difference-between-client-session-and-sso-session-in-timeout-settings/4190 "2020-08-10T02:29:25Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![pmellati](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@pmellati](https://forum.keycloak.org/u/pmellati)\
**Post date:** [August 10, 2020, 2:29am UTC](https://forum.keycloak.org/t/difference-between-client-session-and-sso-session-in-timeout-settings/4190/1 "2020-08-10T02:29:25Z")

</div>

Hi,

We are trying to configure our session timeouts for various clients. However, we are not sure what is meant by “Client Session” and “SSO Session” in the “Realm Settings → Tokens” settings page:

 ![Timeouts](https://global.discourse-cdn.com/free1/uploads/keycloak/original/2X/d/d5cdcb69c6b12ec7dea8c990405360f671a71e42.png)

The tooltip descriptions are a bit vague, and all we can see in the code is that, when calculating the expiry of an access token, the minimum of the two settings is taken:

> <https://github.com/keycloak/keycloak/blob/main/services/src/main/java/org/keycloak/protocol/oidc/TokenManager.java#L820>

So, what is meant by “SSO Session”, and how is it different from a “Client Session”? Does it have to do with the browser or cookies somehow?

---

<div class="post-metadata">

**Author:** ![pmellati](https://avatars.discourse-cdn.com/v4/letter/p/35a633/32.png) [@pmellati](https://forum.keycloak.org/u/pmellati)\
**Post date:** [August 13, 2020, 6:03am UTC](https://forum.keycloak.org/t/difference-between-client-session-and-sso-session-in-timeout-settings/4190/2 "2020-08-13T06:03:04Z")

</div>

Answering my-self:

SSO Session is about the browser cookie, whereas the client session is in regards to refresh tokens.

---

<div class="post-metadata">

**Author:** ![jsebasrv](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/jsebasrv/32/5400_2.png) [@jsebasrv](https://forum.keycloak.org/u/jsebasrv)\
**Post date:** [April 4, 2022, 2:09pm UTC](https://forum.keycloak.org/t/difference-between-client-session-and-sso-session-in-timeout-settings/4190/3 "2022-04-04T14:09:09Z")

</div>

Hello @pmellati, I have several clients and I want to extend browser session time for an specific client. I tried to change anvaced options inside client configuration but doesn´t work. Do you have any advise?
