# SSO Idle Timeout

**URL:** <https://forum.keycloak.org/t/sso-idle-timeout/4125>\
**Category:** Securing applications\
**Tags:** oidc\
**Created:** [August 5, 2020, 8:52am UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125 "2020-08-05T08:52:18Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![EnesToptas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enestoptas/32/1147_2.png) [@EnesToptas](https://forum.keycloak.org/u/EnesToptas)\
**Post date:** [August 5, 2020, 8:52am UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/1 "2020-08-05T08:52:18Z")

</div>

Hello,

I have a nodejs app with a react front end. I want that if a user doesn’t do anything in the browser for a while he must be logged out. So I set the SSO Idle Timeout to 1 minute, for trying. But it doesn’t seem to work. I login to the app and just wait at the page, click on nothing, but even after more than 1 minute, when I refresh the page I am still logged in. How can I solve this?

Also I am leaving my express-session configuration in case it is related to it.

```
app.use(session({

    name: config.SESSION_NAME,

    secret: config.SESSION_SECRET,

    resave: false,

    saveUninitialized: true,

    proxy: true,

    rolling: false,

    cookie: {

        expires: 2*60*60*1000 .

    },

    store: memoryStore

}));
```

---

<div class="post-metadata">

**Author:** ![EnesToptas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enestoptas/32/1147_2.png) [@EnesToptas](https://forum.keycloak.org/u/EnesToptas)\
**Post date:** [August 5, 2020, 10:46am UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/2 "2020-08-05T10:46:10Z")

</div>

UPsie guysss pls im gonna get fired unless i solve this by tomorrow

---

<div class="post-metadata">

**Author:** ![klinux](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/klinux/32/1198_2.png) [@klinux](https://forum.keycloak.org/u/klinux)\
**Post date:** [August 5, 2020, 1:39pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/3 "2020-08-05T13:39:35Z")

</div>

SSO Session Idle Timeout is the time that refresh\_token has to refresh access\_token, what is the configuration of access\_token duration, in option Access Token Lifespan?

And I think that you have to implement a idle in your application, after X time idle, your app have to logout the sessioin.

Are you using the keycloak js libary? I think that some things like that are resolved on the library.

---

<div class="post-metadata">

**Author:** ![EnesToptas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enestoptas/32/1147_2.png) [@EnesToptas](https://forum.keycloak.org/u/EnesToptas)\
**Post date:** [August 5, 2020, 3:51pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/4 "2020-08-05T15:51:26Z")

</div>

Access Token Lifespan is 5 minutes and SSO Session Idle is 30 minutes. Yes I am using the official nodejs adapter. If I have to do it on the server-side, how can I do it?

---

<div class="post-metadata">

**Author:** ![klinux](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/klinux/32/1198_2.png) [@klinux](https://forum.keycloak.org/u/klinux)\
**Post date:** [August 5, 2020, 4:00pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/5 "2020-08-05T16:00:15Z")

</div>

Remember, when you lower the SSO Idle Session, you have to lower the access token lifespan. You have to renew access token before session idle reached. Ex. SSO Idle Session is 1 minut, access token lifespan needs to lower than.

---

<div class="post-metadata">

**Author:** ![EnesToptas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enestoptas/32/1147_2.png) [@EnesToptas](https://forum.keycloak.org/u/EnesToptas)\
**Post date:** [August 5, 2020, 5:36pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/6 "2020-08-05T17:36:02Z")

</div>

I have done that but doing that absolutely does nothing, it doesn’t log me out.

---

<div class="post-metadata">

**Author:** ![rooch84](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/rooch84/32/189_2.png) [@rooch84](https://forum.keycloak.org/u/rooch84)\
**Post date:** [August 12, 2020, 7:34am UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/7 "2020-08-12T07:34:57Z")

</div>

Do you still have your job? If so, do you still need help with this?

---

<div class="post-metadata">

**Author:** ![EnesToptas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enestoptas/32/1147_2.png) [@EnesToptas](https://forum.keycloak.org/u/EnesToptas)\
**Post date:** [August 12, 2020, 10:43am UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/8 "2020-08-12T10:43:53Z")

</div>

YEAH I KEPT MY JOB BUT I HAD TO DO SOME THINGS I REALLY DON’T WANT TO NAME. any help is still more than appreciated.

---

<div class="post-metadata">

**Author:** ![rooch84](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/rooch84/32/189_2.png) [@rooch84](https://forum.keycloak.org/u/rooch84)\
**Post date:** [August 12, 2020, 11:02am UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/9 "2020-08-12T11:02:36Z")

</div>

For a full logout, you need the user to visit the logout end point (/user/logout). You could you use a timeout to redirect them if there is no activity.

---

<div class="post-metadata">

**Author:** ![dominicdettabp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dominicdettabp/32/1232_2.png) [@dominicdettabp](https://forum.keycloak.org/u/dominicdettabp)\
**Post date:** [August 12, 2020, 1:04pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/10 "2020-08-12T13:04:38Z")

</div>

Hi maybe there are some callback events of keycloak adapter js that can help you to develop what you want, read the [doc](https://github.com/keycloak/keycloak-documentation/blob/master/securing_apps/topics/oidc/javascript-adapter.adoc#callback-events).  
If you are using react wrapper I recommend you to read their doc too.

---

<div class="post-metadata">

**Author:** ![dominicdettabp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dominicdettabp/32/1232_2.png) [@dominicdettabp](https://forum.keycloak.org/u/dominicdettabp)\
**Post date:** [August 12, 2020, 2:13pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/11 "2020-08-12T14:13:20Z")

</div>

A solution would be to pass a callback when initializing the keycloak instance which set a timeout function to calculate the expiration and execute logout.

---

<div class="post-metadata">

**Author:** ![EnesToptas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enestoptas/32/1147_2.png) [@EnesToptas](https://forum.keycloak.org/u/EnesToptas)\
**Post date:** [August 12, 2020, 2:26pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/12 "2020-08-12T14:26:56Z")

</div>

Can that determine inactivity? That makes sense though. @dominicdettabp

---

<div class="post-metadata">

**Author:** ![EnesToptas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enestoptas/32/1147_2.png) [@EnesToptas](https://forum.keycloak.org/u/EnesToptas)\
**Post date:** [August 12, 2020, 2:28pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/13 "2020-08-12T14:28:23Z")

</div>

Is there a way to determine inactivity? or do you suggest that I reset the timer in every http request?

---

<div class="post-metadata">

**Author:** ![rooch84](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/rooch84/32/189_2.png) [@rooch84](https://forum.keycloak.org/u/rooch84)\
**Post date:** [August 12, 2020, 2:53pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/14 "2020-08-12T14:53:23Z")

</div>

I would also do the latter. It’s on my backlog, but because I regularly poll for data it’s non-trivial for my use case. I use the endpoint to sign users out of multiple browser sessions.

---

<div class="post-metadata">

**Author:** ![EnesToptas](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/enestoptas/32/1147_2.png) [@EnesToptas](https://forum.keycloak.org/u/EnesToptas)\
**Post date:** [August 12, 2020, 9:12pm UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/15 "2020-08-12T21:12:44Z")

</div>

Ok thanks a lot. Will give it a try.

---

<div class="post-metadata">

**Author:** ![dominicdettabp](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/dominicdettabp/32/1232_2.png) [@dominicdettabp](https://forum.keycloak.org/u/dominicdettabp)\
**Post date:** [August 13, 2020, 6:42am UTC](https://forum.keycloak.org/t/sso-idle-timeout/4125/16 "2020-08-13T06:42:02Z")

</div>

As you already suggested I would reset the timer in every http request.
