Session token invalidation ambiguity for concurrent Salesforce API sessions
0 reputation · 30 Apr 2022, 13:23 UTC
The platform returns a SESSION_EXPIRED error when a session ID expires, yet it does not clarify whether that expiration revokes all concurrent sessions for the user.
Given that JWT Bearer tokens are short‑lived and can remain valid after password changes, and that UI sessions may coexist with API sessions, the exact scope of session invalidation remains undefined.
Does a timed‑out session invalidate only that session or every active session for the user? Can administrators force immediate revocation of all sessions from a single control? How does the behavior differ between UI and API contexts?