A session is an active, authenticated connection to Buttons (a browser tab, or a position running on a control surface), tied to a specific user and how they authenticated. Reviewing sessions can help you confirm who's actually signed in right now, and end a session that shouldn't still be active.
Note
This page is gated behind a feature flag that's off by default in most installations. If Settings → Sessions doesn't appear in your navigation, it isn't currently enabled for your deployment.
Before you begin#
- Access to Settings → Sessions, if it's enabled for your deployment.
Review active sessions#
Open Settings → Sessions (labeled Resource Sessions) for a table of every active session, with columns for User, Type (position or web), Auth Method (None, Identity Only, PIN, Password, Passkey, or OAuth), Started, and Expires.
There's no IP address or device column: use the User and Type columns together with Started/Expires to identify a session you don't recognize.
End a session#
- Open Settings → Sessions.
- Find the session, and select Kick User from its row menu, or select multiple sessions and choose Kick from the bulk action.
- Confirm.
The session ends immediately; whoever was using it will need to authenticate again to continue.
If you get stuck#
What you see | What to try |
|---|
The Sessions page isn't in your navigation at all. | It's behind a feature flag that's off by default: confirm with your Bitfocus contact whether it's meant to be enabled for your deployment. |
You don't recognize a listed session. | Cross-reference its User, Type, and Started time; if it genuinely shouldn't be active, kick it and consider whether that user's password or PIN needs to change. |
A kicked session's user immediately reconnects. | Kicking ends the current session only: if you need to prevent them from signing back in, address that through their user account or role instead. |
Where to go next#