AddThisFeature

Session Management

Let users see and revoke their own sessions.

moderate Security & Reliability

What it adds

A list of active sessions with device and location, and one-click revocation.

What your agent is told to do

4
  1. 1

    Store sessions as records with a user agent, IP, and last-seen timestamp.

  2. 2

    Show the user their active sessions and let them revoke any of them — and all others at once.

  3. 3

    Mark the current session clearly so they don't sign themselves out by accident.

  4. 4

    Revoke all sessions on password change.

Edge cases it handles

4
  • Revocation must take effect IMMEDIATELY, not at next page load. If sessions are cached, invalidate the cache.
  • Sessions must expire on their own — an infinite session is a permanent liability.
  • Don't show a precise geolocation you can't stand behind; a rough city from IP is fine, a wrong one alarms people.
  • Revoking the current session should sign the user out cleanly, not error.

Definition of done

7
  • Users can see active sessions with device and last-seen time.
  • Any session can be revoked, and revocation is immediate.
  • The current session is clearly marked.
  • A password change revokes all other sessions.
  • Sessions expire on their own schedule.
  • The feature matches the existing design system.
  • No existing functionality is broken.

Related features

How it works

  1. 1

    Copy the link

    Grab the Markdown instruction URL for this feature.

  2. 2

    Give it to your AI

    Paste it into Claude Code, Cursor, v0, Lovable — whatever you build with.

  3. 3

    It inspects, then implements

    Your agent reads your existing app first, then adds the feature to fit it.

Works with your stack

These instructions are written to adapt. They tell the agent to detect your framework, match your existing design system, and reuse what you already have — rather than assuming a particular stack.

Need it tighter than that? Customize the feature and tell it exactly what you're running.