Sessions and devices — who is logged into your account
A list of active devices — browsers and handheld scanners — with an option to end each session individually. You cannot end the current session by itself; use “Log out all sessions” for that.
The Active devices and recent logins section shows every device where your account is or has been logged in — both office browsers and warehouse handheld scanners.
Step by step
- Click your avatar in the top-right corner and choose My profile, or use Manage sessions in the panel on the left.
- Open the Security tab and scroll to Active devices and recent logins.
- Review the entries. Current marks the browser you are using now; Ended means the session is no longer active.
- End an unfamiliar session using End this session beside it. Session ended. confirms the action.
- If the device is labelled 2FA trusted until, remove its exemption with Revoke 2FA trust. The session remains, but the next login will require a code — confirmed by Device trust revoked — 2FA code will be required at next login.
- To log out everywhere at once, click Log out all sessions. In the confirmation dialog, enter your Current password and click Log out everywhere.
- You will be redirected to the login screen with All sessions ended — redirecting to login.
- Note that personal API tokens remain untouched — if you suspect a leak, revoke them separately (API keys — your personal tokens).
What an entry shows
The browser you are currently using has a Current badge; inactive sessions are labelled Ended. If a device is remembered for 2FA, you will also see the “2FA trusted until…” date.
One login equals one session
Logging out on one device does not affect the others. Each login has its own key, so signing out from a handheld scanner — manually or after inactivity — leaves everything else logged in.
This is a change. Previously the whole account had one shared key, so any logout invalidated it on every device. An operator who took another scanner from the dock logged out the colleague working on the first one — without warning, in the middle of their work.
Log out all sessions still works as before: it ends everything, including the current session.
End one session
Every session except the current one has an End this session action. The person using that device is logged out.
This works for scanners too. Previously, the list could terminate only a browser session and refused for a scanner. Now this is the right way to close an account left logged in on a terminal that has been returned to the dock.
You cannot end the current session individually — use the button below. The card description says this directly: end the current browser with “Log out everywhere.”
Log out all sessions
This ends all sessions, including the current one. Enter your current password and, after confirmation, you are redirected to the login screen.
One important detail: personal API tokens are left untouched. A scanner or automation using a token will keep working. If you suspect that more than your password was exposed, revoke the tokens too (API keys — your personal tokens).
2FA trust
A device marked as trusted does not ask for a 2FA code at each login until the stated date. Revoke 2FA trust removes that exemption without ending the session — a code will be required again at the next login.
This is a good first step if you left a browser logged in on someone else’s computer and want to make sure that the address alone is not enough to get back in.
If you suspect your account was compromised
Follow this order:
- Change your password (Changing your own password — requirements and when confirmation is needed) — by itself, this does not log out other devices.
- Log out all sessions.
- Revoke any API tokens you do not recognize.
- Enable 2FA if it is not already enabled (Two-factor authentication (2FA) — enabling it, backup codes, and disabling it).
Steps 1 and 2 are separate actions. Changing your password alone leaves an intruder logged in.
Want to see this with your orders? We’ll show you NOXTI with your sales channels and warehouse.
Book a demo