# Invalidate backend session

**URL:** <https://forum.keycloak.org/t/invalidate-backend-session/3920>\
**Category:** Securing applications\
**Tags:** adapter-java\
**Created:** [July 23, 2020, 6:29am UTC](https://forum.keycloak.org/t/invalidate-backend-session/3920 "2020-07-23T06:29:47Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![andr0id1](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/andr0id1/32/1503_2.png) [@andr0id1](https://forum.keycloak.org/u/andr0id1)\
**Post date:** [July 23, 2020, 6:29am UTC](https://forum.keycloak.org/t/invalidate-backend-session/3920/1 "2020-07-23T06:29:47Z")

</div>

I use React with Spring Boot as a Backend. To use Keycloak I added the “keycloak-spring-boot-starter” dependency. It’s working good, I can use my token to request things from it, but there is one problem. If I logout and my session in Keycloak is deleted, I can still use the token to request things from Spring Boot. It works until the token is not valid anymore (3 minutes). How can I make sure that the backend won’t accept the token anymore or ask Keyclaok again if it’s still valid?

---

<div class="post-metadata">

**Author:** ![dasniko](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dasniko/32/2969_2.png) [@dasniko](https://forum.keycloak.org/u/dasniko)\
**Post date:** [July 23, 2020, 7:34am UTC](https://forum.keycloak.org/t/invalidate-backend-session/3920/2 "2020-07-23T07:34:35Z")

</div>

That’s the nature of JWTs - they are “self-containing” and can be used until expired.

In case you want your session in your backend ist invalidated when logging out at Keycloak, use the admin-url configuration (see [https://www.keycloak.org/docs/latest/server\_admin/#oidc-clients](https://www.keycloak.org/docs/latest/server_admin/#oidc-clients) and scroll down to “Admin URL”.

To check in Keycloak if a token is still valid, you can use the token\_introspection endpoint, this is part of the authorization services, somewhere in [https://www.keycloak.org/docs/latest/authorization\_services/index.html](https://www.keycloak.org/docs/latest/authorization_services/index.html)
