Configure User Session Timeout
Set the maximum idle time and the maximum session time for every user of an account with the Azion API.
You can set the User Session Timeout policy through the Azion API. The maximum idle time ends a session after a period of inactivity. The maximum session time ends a session after a total duration, so no session stays open indefinitely. To block a user after failed sign-in attempts instead, refer to Configure Account Lockout Policy.
Prerequisites
- Account Owner privileges. A request from any other user returns Error 403.
- A personal token for the
Authorizationheader. To create one, refer to Manage personal tokens.
The policy is available with every Azion Support tier. For the tiers, refer to Support guidelines. The policy an organization sets applies to every account level under it.
Read the current timeouts
Read the stored values before you change them.
Send a GET request to the auth/policies/session endpoint:
The response is similar to this one:
max_idle_time sets how long an idle session lasts, and max_session_time how long any session lasts, both in minutes.
Change the timeouts
Both keys take a value in minutes:
| Key | Type | Description |
|---|---|---|
max_idle_time | Integer | Period of inactivity after which a session ends automatically. The value is in minutes. Default value and maximum idle time allowed: 1440, which is 1 day |
max_session_time | Integer | Total time a session can stay active, whatever the activity, so sessions do not stay open indefinitely. The value is in minutes, from 5 minutes to 21600 minutes, which is 15 days. Default value: 21600 |
Send a PUT request to the auth/policies/session endpoint:
The response is similar to this one:
The policy uses the new values for the sessions on the account.
For every endpoint the API exposes, refer to the Azion API reference.