Changelog
Guides

Sign users out

Sign users out of the cookie, Identity bearer, and JWT stacks.

Each sign-in stack has its own logout route, and each one behaves differently. Use the section for your stack.

StackEndpointNeeds a signed-in userCSRFWhat it ends
CookiePOST /identity/logoutYesYesThe application, external, two-factor, remember-client, and ReAuth cookies
Identity bearerPOST /identity/logoutYesNoCookies only. Bearer tokens stay valid until they expire.
JWTPOST /auth/logoutNoYesThe refresh-token family and the refresh cookie
  1. Get a CSRF token from GET /identity/csrfToken.
  2. Send POST /identity/logout with credentials: 'include' and the RequestVerificationToken header.
    const { csrfToken } = await fetch('/identity/csrfToken', { credentials: 'include' }).then(r => r.json());
    await fetch('/identity/logout', {
      method: 'POST',
      credentials: 'include',
      headers: { 'RequestVerificationToken': csrfToken }
    });
    

Logout signs out of the Identity.Application, Identity.External, Identity.TwoFactorUserId, Identity.TwoFactorRememberMe, and AuthEndpoints.ReAuth schemes. Because it clears the remember-client cookie, the next password login from that browser asks for a 2FA code again.

Sign out of the Identity bearer stack

Send POST /identity/logout with the Authorization: Bearer <accessToken> header. No CSRF token is needed.

This call clears cookies only. It does not revoke the access token or the refresh token. To end the session on the client, delete both tokens from storage. The tokens stay valid on the server until they expire.

Sign out of the JWT stack

  1. Get a CSRF token from GET /auth/csrfToken.
  2. Send POST /auth/logout with credentials: 'include' and the RequestVerificationToken header.
  3. Delete the access token from client memory.

The endpoint does not require a signed-in user. It revokes the whole refresh-token family of the cookie it receives, deletes the cookie, and returns 200. The access token stays valid until it expires (15 minutes by default, AccessTokenLifetime).