October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Node.js OTP Security: List Active Sessions and Revoke One Safely

OTP authenticates the user; the session secret authorizes later requests. Build a session list and revocation flow that protects ownership, avoids exposing credentials, and accounts for JWTs that may outlive a user-visible session.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

OTP verifies a user during authentication; it is not what authorizes every later request. After OTP succeeds, the application’s session secret carries authenticated access, so a session must be protected and revocable on its own. In a Node.js app, the safe pattern is to show only the signed-in user’s session metadata, require fresh authentication before session-management actions, and invalidate the selected session on the server.

How OTP and sessions work together

An OTP is an authentication factor used to establish or strengthen identity. Once authentication succeeds, a session secret—such as a server-side session identifier or a token—typically carries that authenticated state across later requests. Treat the secret as highly sensitive: for its lifetime, it can be equivalent to the strongest authentication method used, including OTP. Do not put it in a session list, expose it in an API response, or write it to logs. OWASP recommends a salted hash when session correlation in logs is necessary; see the OWASP Session Management Cheat Sheet.

Whether your Node.js app uses server-side session records or self-contained tokens changes what “revoke” actually does. The framework and storage choice determine the specific API and data model, so the design below describes the security properties rather than prescribing package calls.

How can a user see where their account is logged in?

Provide an authenticated session-management view backed by records associated with an immutable user identifier. The server must derive that identifier from the authenticated request, not trust a user ID supplied in the request body or URL as authority. Return useful context, never credentials.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Useful metadata: session creation time, last activity, a device or browser label, and approximate IP or location information where the app can provide it responsibly. OWASP recommends tracking client details such as IP address, User-Agent, login time, and idle time.
  • Never display: a raw session ID, refresh token, OTP secret, or other bearer credential.
  • Interpret labels cautiously: user-agent and IP-derived details help a person recognize a session, but they are not proof of identity or device ownership.
  • Control access: keep session metadata available only to the authenticated account and protect the endpoint like other sensitive account functions.

OWASP ASVS 5.0 requirement 7.5.2 says users should be able to view active sessions and, after authenticating again with at least one factor, terminate any or all of them. The wording and related requirements are in the OWASP Application Security Verification Standard (ASVS).

How do you revoke one stateful session safely?

With a stateful or reference-session design, the backend checks session state as requests arrive. Revoking a session therefore means invalidating its server-side record so it cannot authorize another request. Scope the operation to both the authenticated user and the selected session record. A guessed or copied record ID must not let one account terminate another account’s session.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Reauthenticate: require the user to authenticate again with at least one factor before listing or terminating sessions. For particularly sensitive account changes, require full reauthentication. After reauthentication, renew the session token and invalidate the prior token where appropriate, as recommended by OWASP ASVS and the OWASP Authentication Cheat Sheet.
  2. Use a destructive operation: expose a DELETE-style endpoint or equivalent operation for termination. If cookie authentication is used, protect the request against CSRF with a defense appropriate to the framework and HTTP method. NIST SP 800-63B-4 says POST/PUT content should contain a session identifier verified by the relying party as a CSRF protection measure.
  3. Enforce ownership in the data operation: find or delete the target using both the caller’s authenticated user ID and the requested session record ID. Do not fetch by session record ID alone and rely on a later check.
  4. Invalidate before reporting success: ensure the backend will reject the selected session on subsequent requests. If it is the current browser’s session, also clear that browser’s cookie. Return a success status without returning the session secret.

ASVS requirement 7.4.1 requires that after session termination, including logout or expiration, the application disallow further use of that session. A confirmation in the interface is not revocation unless the server-side authorization state has actually changed.

Does revoking a session make a JWT stop working immediately?

Not necessarily. A self-contained token can remain cryptographically valid after an app marks a corresponding user-facing session record as revoked. If the application verifies the token locally and never checks revocation state, deleting a database row alone does not make that token unusable before its expiry.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Design How one session is revoked What requests must do Operational consideration
Stateful/reference session Invalidate the selected backend session record. Check backend session state so a terminated record cannot authorize requests. Requires backend state and a lookup or equivalent state check.
Self-contained token A session-row change may not revoke the token. Options include a terminated-token list, a per-user issuance cutoff, or rotating a per-user signing key. Consult revocation state or an equivalent control if requests must reject a token before its natural expiry. Stateless validation is possible, but prompt revocation needs coordination. Include associated refresh tokens in the revocation design where issued.

Choose token revocation controls based on the required revocation delay, scale, and token architecture. Neither approach is universally faster or more scalable based on the security requirements alone. NIST also distinguishes an authentication session from access and refresh tokens: those tokens can remain valid after the session ends. See NIST SP 800-63B-4.

What session controls should a Node.js app enforce?

Session management belongs on the server, even when the browser also stores an expiry time or clears a cookie. Define inactivity and absolute lifetime limits based on the application’s risk, assurance level, environment, and endpoint; neither OWASP nor NIST establishes one universal timeout for every app. Enforce expiry server-side, invalidate sessions at logout or expiration, and do not let a cookie’s expiry substitute for that enforcement.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Generate strong secrets: NIST SP 800-63B-4 (2025) says session secrets should come from an approved random bit generator and be at least 64 bits. OWASP ASVS 5.0 specifies at least 128 bits of entropy for reference session tokens. These are requirements, not incident or adoption statistics.
  • Protect cookies and transport: require HTTPS, scope cookie hostnames and paths narrowly, and use HttpOnly where appropriate. NIST prefers the __Host- prefix, Path=/, and SameSite=Lax or SameSite=Strict. Never permit session secrets to fall back to insecure transport.
  • Consider persistence carefully: NIST says bearer session secrets generally should not persist across an application restart or device reboot. Design session, access-token, and refresh-token lifetimes as distinct controls.
  • Renew at authentication events: after reauthentication, issue a renewed session token and invalidate the prior one as appropriate to reduce session-fixation risk.

Document why the timeout values fit the app’s risks; ASVS calls for documented inactivity and absolute lifetime limits, while NIST notes that appropriate limits depend on context.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

When else should sessions be terminated?

Session revocation is part of the account lifecycle, not only a “log out this device” feature. OWASP ASVS calls for terminating all sessions when an account is disabled or deleted, and for offering users the option to terminate other sessions after an authentication-factor change. That gives a user who changes or replaces an OTP factor a way to end access on devices they do not control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.