Skip to main content

Session Management

useSession reads the authenticated profile and the server-side sessions provided by @ovok/core. It refreshes when the app returns to the foreground by default and broadcasts logout changes to other mounted consumers.

import { Button, Text } from "react-native";
import { SessionList, useSession } from "@ovok/native";

const SecurityScreen = () => {
const {
status,
sessions,
loading,
error,
logout,
revokeSessions,
refreshSessions,
} = useSession({ sessions: true, refreshOnForeground: true });

return (
<>
<SessionList />
{status === "authenticated" && (
<Button
title={`Sign out of ${sessions.length} session(s)`}
onPress={() => revokeSessions("other")}
/>
)}
<Button title="Refresh sessions" onPress={refreshSessions} disabled={loading} />
{error && <Text>{error.message}</Text>}
{status === "authenticated" && <Button title="Log out" onPress={logout} />}
</>
);
};

The hook returns status (loading, authenticated, or signed-out), isAuthenticated, profile, normalized sessions, loading, an optional error, and refresh, refreshSessions, logout, and revokeSessions methods. Pass sessions: false when a screen only needs profile state; session refreshes then return an empty array without calling the session endpoint. Pass refreshOnForeground: false when the host owns app-resume refreshes.

LogoutButton calls @ovok/core's server-side logout() method. That endpoint revokes the current server session before the local login is cleared. SessionList exposes the sessions returned by the backend and a “Sign out of other devices” action using revokeSessions("other").

Each session is normalized to { id, authMethod?, remoteAddress?, lastUpdated? }. Older core response fields such as ip, lastActiveAt, and createdAt are mapped to the normalized names. Apps with custom authentication flows can call refresh() after sign-in or a token refresh. The session API requires the published @ovok/core version that includes logout, getSessions, and revokeSessions.