Files
supabase/apps/docs/content/guides/auth/signout.mdx
Katerina Skroumpelou 028e05205b docs: warn that default signOut scope revokes all sessions (#50119)
Warn that default signOut scope revokes all sessions. Motivation:
https://github.com/supabase/ssr/issues/68

<!-- This is an auto-generated comment: release notes by coderabbit.ai
-->

## Summary by CodeRabbit

* **Documentation**
* Clarified that signing out without a specified scope ends all sessions
by default.
* Added guidance for using a local sign-out scope to preserve sessions
on other devices and browsers.
* Documented the invalid refresh token errors that may occur when other
sessions are revoked.

<!-- end of auto-generated comment: release notes by coderabbit.ai -->
2026-09-10 12:37:06 +00:00

173 lines
4.0 KiB
Plaintext

---
title: 'Signing out'
subtitle: 'Signing out a user'
---
Signing out a user works the same way no matter what method they used to sign in.
Call the sign out method from the client library. It removes the active session and clears Auth data from the storage medium.
<Tabs
scrollable
size="small"
type="underlined"
defaultActiveId="js"
queryGroup="language"
>
<TabPanel id="js" label="JavaScript">
```js
import { createClient } from '@supabase/supabase-js'
const supabase = createClient('https://your-project-id.supabase.co', 'sb_publishable_...')
// ---cut---
async function signOut() {
const { error } = await supabase.auth.signOut()
}
```
</TabPanel>
<$Show if="sdk:dart">
<TabPanel id="dart" label="Dart">
```dart
Future<void> signOut() async {
await supabase.auth.signOut();
}
```
</TabPanel>
</$Show>
<$Show if="sdk:swift">
<TabPanel id="swift" label="Swift">
```swift
try await supabase.auth.signOut()
```
</TabPanel>
</$Show>
<$Show if="sdk:kotlin">
<TabPanel id="kotlin" label="Kotlin">
```kotlin
suspend fun logout() {
supabase.auth.signOut()
}
```
</TabPanel>
</$Show>
<$Show if="sdk:python">
<TabPanel id="python" label="Python">
```python
supabase.auth.sign_out()
```
</TabPanel>
</$Show>
<$Show if="sdk:csharp">
<TabPanel id="csharp" label="C#">
```c#
await supabase.Auth.SignOut();
```
</TabPanel>
</$Show>
</Tabs>
## Sign out and scopes
Supabase Auth allows you to specify three different scopes for when a user invokes the [sign out API](/docs/reference/javascript/auth-signout) in your application:
- `global` (default) when all sessions active for the user are terminated.
- `local` which only terminates the current session for the user but keep sessions on other devices or browsers active.
- `others` to terminate all but the current session for the user.
You can invoke these by providing the `scope` option:
<Admonition type="caution">
JavaScript, Swift, Python, and C# default to the `global` scope. Dart and Kotlin default to `local`.
With the `global` scope, calling `signOut()` on one device revokes the refresh tokens for every session that user has, including other devices and browsers. Those other sessions fail with `AuthApiError: Invalid Refresh Token: Refresh Token Not Found` the next time they try to refresh, even though no one signed out on that device.
If your app expects independent sessions per device, pass the `local` scope explicitly, as shown in the examples below.
</Admonition>
<Tabs
scrollable
size="small"
type="underlined"
defaultActiveId="js"
queryGroup="language"
>
<TabPanel id="js" label="JavaScript">
```js
import { createClient } from '@supabase/supabase-js'
const supabase = createClient('https://your-project-id.supabase.co', 'sb_publishable_...')
// ---cut---
// defaults to the global scope
await supabase.auth.signOut()
// sign out from the current session only
await supabase.auth.signOut({ scope: 'local' })
```
</TabPanel>
<$Show if="sdk:dart">
<TabPanel id="dart" label="Dart">
```dart
// defaults to the local scope
await supabase.auth.signOut();
// sign out from all sessions
await supabase.auth.signOut(scope: SignOutScope.global);
```
</TabPanel>
</$Show>
<$Show if="sdk:kotlin">
<TabPanel id="kotlin" label="Kotlin">
```kotlin
// defaults to the local scope
await supabase.auth.signOut();
// sign out from all sessions
supabase.auth.signOut(SignOutScope.GLOBAL)
```
</TabPanel>
</$Show>
<$Show if="sdk:csharp">
<TabPanel id="csharp" label="C#">
```c#
// defaults to the global scope
await supabase.Auth.SignOut();
// sign out from the current session only
await supabase.Auth.SignOut(SignOutScope.Local);
```
</TabPanel>
</$Show>
</Tabs>
Upon sign out, all refresh tokens and potentially other database objects related to the affected sessions are destroyed and the client library removes the session stored in the local storage medium.
<Admonition type="caution">
Access Tokens of revoked sessions remain valid until their expiry time, encoded in the `exp` claim. The user won't be immediately logged out and will only be logged out when the Access Token expires.
</Admonition>