# Remove Token When Session Terminates

**URL:** <https://forum.keycloak.org/t/remove-token-when-session-terminates/7679>\
**Category:** Configuring the server\
**Created:** [March 2, 2021, 10:14am UTC](https://forum.keycloak.org/t/remove-token-when-session-terminates/7679 "2021-03-02T10:14:45Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![amrsaeedhosny](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/amrsaeedhosny/32/2173_2.png) [@amrsaeedhosny](https://forum.keycloak.org/u/amrsaeedhosny)\
**Post date:** [March 2, 2021, 10:14am UTC](https://forum.keycloak.org/t/remove-token-when-session-terminates/7679/1 "2021-03-02T10:14:45Z")

</div>

When I click login to my web app it redirects me to the Keycloak page to log in. After that, the Keycloak page redirects me to my app with an access\_token and refresh\_token. If the access\_token expired it silently refreshes itself with the refresh token.

The problem is if I went to the Keycloak page to sign out, the access\_token keeps working infinitely and doesn’t expire. How to prevent using tokens when the session terminated.

I use SpringBoot for the back-end and Angular for the front-end with angular-oauth2-oidc.
