Account & sign-in · Unlocking & devices

Active sessions: see and revoke your devices

Password only accounts keep an encrypted unlock session per device. See them in Settings › Security and Privacy, and revoke one to sign other devices out.

WiA·3 min·Updated 11 Sept 2026·Verified against app release 2026.09
Screenshots for
Same steps on every device — only the pictures change. Show all

With the Password only unlock method, each device you sign in on keeps an encrypted session so it can re-open your keys without asking for the password every time. The Active Sessions list shows those devices and lets you cut one off. Because the server enforces revocation as a single cut-off time on your account, revoking one session signs out every other device — the one you are using is the only one that survives.

Passphrase accounts have no session list

If your unlock method is Passphrase, nothing is stored on the server per device and the Active Sessions section is not shown. Your protection there is the passphrase itself: a device that does not have it cannot open your mail. To shut out a lost device, see the last question below.

See your sessions

  1. Open Settings and choose Security and Privacy.
    1Security and Privacy2Two-factor section3Unlock Method — Active Sessions follows belowWeb & desktop
    Settings › Security and Privacy. Active Sessions sits below Unlock Method for Password only accounts.12
    1Two-factor section2Unlock Method — Active Sessions follows belowiPhone
    Settings › Security and Privacy. Active Sessions sits below Unlock Method for Password only accounts.12
    1Two-factor section2Unlock Method — Active Sessions follows belowAndroid
  2. Scroll to Active Sessions. Each card shows the device's name — for example macOS - Chrome 128 or the phone's model name — and three times: Created, Last used and Expires.
    Web & desktop screenshotTwo devices listed with Created, Last used and Expires, a Revoke button on each, and Revoke All Other Sessions underneath.This capture is produced by the screenshot pipeline and will appear here.
    Two devices listed with Created, Last used and Expires, a Revoke button on each, and Revoke All Other Sessions underneath.Web & desktop
    iPhone screenshotTwo devices listed with Created, Last used and Expires, a Revoke button on each, and Revoke All Other Sessions underneath.Same screen as on the web, single column. This capture is produced by the screenshot pipeline and will appear here.
    Two devices listed with Created, Last used and Expires, a Revoke button on each, and Revoke All Other Sessions underneath.iPhone
    Android screenshotTwo devices listed with Created, Last used and Expires, a Revoke button on each, and Revoke All Other Sessions underneath.Same screen as on the web, single column. This capture is produced by the screenshot pipeline and will appear here.
    Two devices listed with Created, Last used and Expires, a Revoke button on each, and Revoke All Other Sessions underneath.Android

The device name is chosen by the device itself and stored encrypted with your master key, so the server holds it but cannot read it; only your unlocked devices can. If a session was created without a name it is listed as Device 1, Device 2, and so on.

Revoke a device

  1. Click Revoke on the card you want to end.
  2. Read the confirmation: Revoke access for "…"? Every other device is signed out at the same time, so you will need to sign in again on all of them. This device stays signed in. Click Revoke.
  3. Every other browser and phone on the account loses its sign-in immediately. The next thing they do — refresh, open a message, receive a live update — fails with Session is no longer valid. Please sign in again. and they are returned to the sign-in page. Their cached mail is cleared with the sign-in.

When two or more sessions are listed, a Revoke All Other Sessions button appears underneath. It has the same effect on other devices, and additionally removes this device's quick-unlock session too: you stay signed in for now, but the next time this device has to re-open your keys — after a lock, a reload or a restart — you sign in with your password again.

What a revoked device can and cannot do

Revocation kills the device's sign-in tokens, so it can no longer fetch mail, send, or open a live connection. It does not reach into the device: anything already decrypted and on screen there stays visible until the app notices, and anything the device had downloaded earlier may remain in its browser storage until the sign-in is cleared. For a lost device, revoke first, then change your password so the old one is useless if it was seen.

How long a session lasts

  • A session expires 7 days after it was created. Using the device does not extend it; the screen's wording — Sessions expire after 7 days of inactivity — understates this. When it expires, that device is signed out and you sign in with your password again, which creates a fresh session.
  • The sign-in tokens behind a session are separate: an access token lasts 30 minutes and is refreshed automatically for up to 90 days. Revocation cuts both off at once.
  • Log out on a Password only device revokes its session the same way, so logging out anywhere signs out everywhere. See Lock the app or log out.

What our server sees

Cannot see

  • The device names in readable form — they are encrypted with your master key
  • Your keys or password — the server stores one half of a session secret; the other half never leaves the device

Can see

  • How many sessions exist, when each was created, last used and will expire
  • The moment you revoked, which is the cut-off applied to every other device

Common questions

Why did revoking one phone sign out my laptop as well?

Revocation is a single timestamp on your account: every token issued before it is refused. The server cannot spare one device except the one that made the request, which it hands fresh tokens. Sign in again on the laptop; its session is recreated.

I don't see "Active Sessions" in Security and Privacy

It appears only for accounts using the Password only method that have a password set. Passphrase accounts, and accounts created from a chat invitation that have not yet set a password, do not have it. See Choose your unlock method.

Can I rename a device?

No. The name is generated when the session is created — operating system and browser on the web, the device's own name in the apps.

My account uses Passphrase and a device was lost

The device cannot open your mail without the passphrase, unless it was already unlocked — an iPhone keeps the passphrase after its first unlock, and a paired device holds the key itself. Log out is not possible remotely for Passphrase accounts, so change your passphrase — the lost device's copy stops working — and ask support if you need the device's sign-in ended as well.

Article account/active-sessionsScreenshots regenerated automatically for release 2026.09