---
name: azion-configure-user-session-timeout
description: >-
  Set the maximum idle time and the maximum session time for every user of an account with the Azion API.
---

# Configure User Session Timeout

**Preview**

You can set the [User Session Timeout](/en/documentation/fundamentals/user-session-timeout/) policy through the Azion API. The **maximum idle time** ends a session after a period of inactivity. The **maximum session time** ends a session after a total duration, so no session stays open indefinitely. To block a user after failed sign-in attempts instead, refer to [Configure Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/configure-account-lockout-policy/).

---

## Prerequisites

- *Account Owner* privileges. A request from any other user returns *Error 403*.
- A personal token for the `Authorization` header. To create one, refer to [Manage personal tokens](/en/documentation/guides/platform/account-and-billing/personal-tokens/).

The policy is available with every Azion Support tier. For the tiers, refer to [Support guidelines](/en/documentation/support/). The policy an organization sets applies to every account level under it.

---

## Read the current timeouts

Read the stored values before you change them.

Send a `GET` request to the `auth/policies/session` endpoint:

```bash
curl --request GET \
  --url https://api.azion.com/v4/auth/policies/session \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]'
```

The response is similar to this one:

```json
{
  "data": {
    "max_idle_time": 1,
    "max_session_time": 5
  }
```

`max_idle_time` sets how long an idle session lasts, and `max_session_time` how long any session lasts, both in *minutes*.

---

## Change the timeouts

Both keys take a value in *minutes*:

| Key                | Type    | Description                                                                                                                                                                                                        |
| ------------------ | ------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| `max_idle_time`    | Integer | Period of inactivity after which a session ends automatically. The value is in *minutes*. Default value and maximum idle time allowed: `1440`, which is *1 day*                                                    |
| `max_session_time` | Integer | Total time a session can stay active, whatever the activity, so sessions do not stay open indefinitely. The value is in *minutes*, from `5` minutes to `21600` minutes, which is *15 days*. Default value: `21600` |

Send a `PUT` request to the `auth/policies/session` endpoint:

```bash
curl --request PUT \
  --url https://api.azion.com/v4/auth/policies/session \
  --header 'Accept: application/json' \
  --header 'Authorization: Token [TOKEN VALUE]' \
  --header 'Content-Type: application/json' \
  --data '{
  "max_idle_time": 1,
  "max_session_time": 5
}'
```

The response is similar to this one:

```json
{
  "state": "executed",
  "data": {
    "max_idle_time": 1,
    "max_session_time": 5
  }
```

The policy uses the new values for the sessions on the account.

For every endpoint the API exposes, refer to the [Azion API reference](https://api.azion.com/).

---

## Next steps

- [User Session Timeout](/en/documentation/fundamentals/user-session-timeout.md): Read how the idle and session limits end a session.
- [Configure Account Lockout Policy](/en/documentation/guides/application-security/access-and-compliance/configure-account-lockout-policy.md): Lock a user after repeated failed sign-in attempts.
- [Manage conditional access by IP address](/en/documentation/guides/application-security/access-and-compliance/conditional-access-by-ip-address.md): Allow access to the account only from listed IP addresses.
- [Enable multi-factor authentication](/en/documentation/guides/platform/account-and-billing/multi-factor-authentication.md): Ask every user for an authenticator code at sign-in.
