---
# @generated by sylphx-gen 0.1.0 from contracts@e145cc7cf1bc9605f2b27439e5e17ed76a1a2fd7e7021906a013f7565e4a0cd5. Do not edit.
title: "Sessions"
description: "The `sessions` collection of Sylphx Auth: A Session is an opaque Auth session of an end user, issued by a sign-in ceremony."
type: reference
product: auth
summary: "A Session is an opaque Auth session of an end user, issued by a sign-in ceremony."
updated: 2026-09-28
order: 900
---

A Session is an opaque Auth session of an end user, issued by a sign-in ceremony. Sessions are revoked, never deleted; revocation is a CAEP signal delivered through Sylphx Events.

**Service** Sylphx Auth · **Resource type** `auth.sylphx.com/Session` · **Name pattern** `orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}/sessions/{session}` · **Shape** `record`

## Fields

| Field | Type | What it is |
| --- | --- | --- |
| `name` | `string` | `orgs/{org}/projects/{project}/envs/{env}/end_users/{end_user}/sessions/{session}`. |
| `uid` | `string` | `ses_<cell><ulid>`; never reused. Output only. |
| `meta` | `ResourceMeta` | Resource metadata. |
| `state` | `SessionState` | The session state. Output only. One of `active`, `revoked`, `expired`. |
| `assurance` | `AuthMethod` | How the session was established. Output only. One of `password`, `magic_link`, `email_otp`, `passkey`, `totp`, `oidc`, `saml`. |
| `mfa` | `bool` | Whether a second factor was presented. Output only. |
| `active_organization` | `string` | The active customer organization. Output only. |
| `oauth_client` | `string` | The OAuth client the session signed in to, if any. Output only. |
| `ip_address` | `string` | The client IP at sign-in. Output only. |
| `user_agent` | `string` | The user agent at sign-in. Output only. |
| `last_active_time` | `timestamp` | The last authenticated use. Output only. |
| `expire_time` | `timestamp` | When the session expires. Output only. |
| `revoke_time` | `timestamp` | When the session was revoked. Output only. |
| `revoke_reason` | `SessionRevokeReason` | Why the session was revoked. Output only. One of `sign_out`, `user`, `admin`, `session_limit`, `recovery`, `suspended`, `deleted`, `fingerprint`. |

## Methods

Every method of the collection, in the registry's order, with the scope it
needs. The full request, response and examples are one link away.

| Method | Call | What it does |
| --- | --- | --- |
| `GET` | [`get`](/docs/api/sessions#get) | Gets a session. |
| `GET` | [`list`](/docs/api/sessions#list) | Lists sessions. |
| `POST` | [`revoke`](/docs/api/sessions#revoke) | Revokes a session. |

## get

Gets a session.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/sessions/session` · scope `auth:read` · effect `read` · [Request, response and examples](/docs/api/sessions/get)

## list

Lists sessions.

`GET https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/sessions` · scope `auth:read` · effect `read` · paginated · [Request, response and examples](/docs/api/sessions/list)

## revoke

Revokes a session.

`POST https://api.sylphx.com/v1/orgs/acme/projects/shop/envs/production/end_users/end-user/sessions/session:revoke` · scope `auth:write` · effect `destructive` · [Request, response and examples](/docs/api/sessions/revoke)
