Universal Logout

Universal Logout is the centrally triggered, simultaneous termination of all active sessions of a user and the revocation of their tokens across several connected applications. The aim is to close existing access immediately when an account is compromised, the risk changes or access is no longer permissible.

The background is a gap in classic single sign-on architectures: when an account is locked at the identity provider, application sessions already open and refresh tokens already issued often remain valid. Logout standards such as SAML Single Logout or OpenID Connect Back-Channel Logout mostly start from the logout performed by the user. Universal logout, by contrast, is triggered by security events or administrators and also includes long-lived tokens. Related is Continuous Access Evaluation (CAE); both can be implemented via the OpenID Foundation's Shared Signals Framework, for example with the event type “session-revoked”.

As a product term, universal logout is used above all by Okta, which offers the function as part of its Identity Threat Protection: if the platform detects a risk, it automatically terminates sessions in supported applications. Generically, this corresponds to event-driven, cross-application session and token termination. The mechanism complements Identity Threat Detection and Response (ITDR) with an immediate response and is part of Identity Security.