Documentation
Client SDK
Logout

Logout

Ending a session closes it on the Secrecy servers and wipes the credentials stored in the browser, so the keys are no longer available on the device.

Log the user out

The secrecyClient.logout method closes the current session when called without argument. It also clears the stored session, identities, key pairs and JWT, along with the client caches.

auth.ts
const logout = async (): Promise<boolean> => {
  // First we need to check if the secrecyClient is available
  if (!secrecyClient) {
    return false;
  }
 
  try {
    // Without argument, the current session is closed
    await secrecyClient.logout();
 
    return true;
  } catch (error) {
    console.error(error);
    return false;
  }
};
⚠️

After a logout, the client is no longer usable. Start a new login to get an authenticated client again.

Close another session

Passing a session identifier closes that session only, and leaves the local credentials untouched. This is how a user revokes a session opened on another device.

auth.ts
const closeSession = async (sessionId: string): Promise<boolean> => {
  // First we need to check if the secrecyClient is available
  if (!secrecyClient) {
    return false;
  }
 
  try {
    await secrecyClient.logout(sessionId);
 
    return true;
  } catch (error) {
    console.error(error);
    return false;
  }
};

React to an expired session

When the server answers an UNAUTHORIZED or FORBIDDEN error, the client logs the user out on its own and reloads the page. The onAccessDenied option lets you run your own handling instead, for example redirecting to your login screen. See the errors page for the full list of error codes.