# Disconnect all sessions/revoking access for all apps of a user

**URL:** <https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955>\
**Category:** ℹ️ Support\
**Tags:** nc13\
**Created:** [September 29, 2018, 11:47pm UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955 "2018-09-29T23:47:50Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![lightonflux](https://help.nextcloud.com/user_avatar/help.nextcloud.com/lightonflux/32/55827_2.png) [@lightonflux](https://help.nextcloud.com/u/lightonflux)\
**Post date:** [September 29, 2018, 11:47pm UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/1 "2018-09-29T23:47:51Z")

</div>

Nextcloud version : 13.0.6

Hello Nextclouders.

On my users security settings page i see all logged in clients. But the list is very long. Like **10 screens** just filled with 3 apps with many sessions/logins for almost every minor version for the last two years.

![screenshot](https://help.nextcloud.com/uploads/default/original/2X/f/fbd3e901565acb439810fcb1fd965aa5fdbde1ef.png)

Is it possible to **revoke access** to these old versions/ **all apps**? I know i can revoke access manually, but that would take hours and several thousands of clicks.

Thank you very much.

---

<div class="post-metadata">

**Author:** ![lightonflux](https://help.nextcloud.com/user_avatar/help.nextcloud.com/lightonflux/32/55827_2.png) [@lightonflux](https://help.nextcloud.com/u/lightonflux)\
**Post date:** [September 30, 2018, 12:22am UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/2 "2018-09-30T00:22:48Z")

</div>

Did not want to wait and came up with this solution:

Go to your personal security site.  
Open developer tools of your browser (Firefox) and select the network tab.  
Revoke access to the oldest app.  
Right click on the DELETE and choose “copy as curl”.  
 ![delete request](https://help.nextcloud.com/uploads/default/original/2X/2/2dab1b5c9c63f09552d92e39b9dc40bb7c6acb03.png)

Create a bash script file with the following content. But replace curl line. Then remove the URL from the curl line and replace it as in the example below.

```
#set -x # for debugging in bash
token=1 # first token to delete
url=https://example.tld/nextcloud/index.php/settings/personal/authtokens/
for i in {1..9999} # 9999 round
do 
	echo "token: $token" # so you see the progress
	curl $url$token -X DELETE -H 'User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0' -H 'Accept: application/json, text/javascript, */*; q=0.01' -H 'Accept-Language: de,en;q=0.5' --compressed -H 'requesttoken:<<<<<censored>>>>>' -H 'OCS-APIREQUEST: true' -H 'X-Requested-With: XMLHttpRequest' -H 'Cookie: nc_sameSiteCookielax=true; nc_sameSiteCookiestrict=true; <<<<<censored>>>>>; oc_sessionPassphrase=<<<<<censored>>>>>; oc_music_volume=56' -H 'DNT: 1' -H 'Connection: keep-alive'
	((token++)) # increase the number
done

```

This is not efficient, and there is probably a way to get the list of tokens that are actually in use. But i wasn’t feeling like researching much for this issue.

**If you have a more efficient solution feel free to answer below.**

---

<div class="post-metadata">

**Author:** ![arucard](https://help.nextcloud.com/letter_avatar/arucard/32/5_5575768a8748004e209b776fc1b2916d.png) [@arucard](https://help.nextcloud.com/u/arucard)\
**Post date:** [June 23, 2022, 10:47am UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/3 "2022-06-23T10:47:28Z")

</div>

This is an older topic but the information is still relevant and was still useful to me (with Nextcloud 24.0.2). So I thought I’d share the small improvement that I could make to what was already provided. I haven’t found any other way to do this

While doing what was described earlier, you can revoke the first and the last session in the list manually. This gives you the start and end token for this list in the dev console. You can also improve the loop by just iterating over these tokes. the code from earlier becomes like this. With 12345 being the first token, from the bottom of the list, and 22345 being the last token, from the top of the list.

```auto
url=https://example.tld/nextcloud/index.php/settings/personal/authtokens/
for token in {12345..22345}
do 
	echo "token: $token" # so you see the progress
	curl $url$token -X DELETE -H 'User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0' -H 'Accept: application/json, text/javascript, */*; q=0.01' -H 'Accept-Language: de,en;q=0.5' --compressed -H 'requesttoken:<<<<<censored>>>>>' -H 'OCS-APIREQUEST: true' -H 'X-Requested-With: XMLHttpRequest' -H 'Cookie: nc_sameSiteCookielax=true; nc_sameSiteCookiestrict=true; <<<<<censored>>>>>; oc_sessionPassphrase=<<<<<censored>>>>>; oc_music_volume=56' -H 'DNT: 1' -H 'Connection: keep-alive'
	((token++)) # increase the number
done

```

---

<div class="post-metadata">

**Author:** ![fluxtop](https://help.nextcloud.com/letter_avatar/fluxtop/32/5_5575768a8748004e209b776fc1b2916d.png) [@fluxtop](https://help.nextcloud.com/u/fluxtop)\
**Post date:** [July 20, 2022, 8:24am UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/4 "2022-07-20T08:24:18Z")

</div>

Thanks so much for posting this. I had to delete 1300 entries. I hope it does not pile up again.

---

<div class="post-metadata">

**Author:** ![devnull](https://help.nextcloud.com/user_avatar/help.nextcloud.com/devnull/32/27793_2.png) [@devnull](https://help.nextcloud.com/u/devnull)\
**Post date:** [July 20, 2022, 8:38am UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/5 "2022-07-20T08:38:05Z")

</div>

There are a lot of issues but nobody implements a feature. And all this has nothing to do with security. What a pity.

[Delete associated devices at once · Issue #8720 · nextcloud/server · GitHub](https://github.com/nextcloud/server/issues/8720)

---

<div class="post-metadata">

**Author:** ![fluxtop](https://help.nextcloud.com/letter_avatar/fluxtop/32/5_5575768a8748004e209b776fc1b2916d.png) [@fluxtop](https://help.nextcloud.com/u/fluxtop)\
**Post date:** [July 20, 2022, 12:35pm UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/6 "2022-07-20T12:35:30Z")

</div>

Just had a look in Settings → Security

Since I deleted 1300 sessions, there are already 10 new ones. Seems like some kind of garbage collection is needed.

---

<div class="post-metadata">

**Author:** ![fluxtop](https://help.nextcloud.com/letter_avatar/fluxtop/32/5_5575768a8748004e209b776fc1b2916d.png) [@fluxtop](https://help.nextcloud.com/u/fluxtop)\
**Post date:** [July 21, 2022, 11:01am UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/7 "2022-07-21T11:01:50Z")

</div>

BTW: The only reason why I was looking for these sessions was, that a login took more than three minutes. After deleting the sessions login was back to normal.

---

<div class="post-metadata">

**Author:** ![Pelzlurch](https://help.nextcloud.com/user_avatar/help.nextcloud.com/pelzlurch/32/44886_2.png) [@Pelzlurch](https://help.nextcloud.com/u/Pelzlurch)\
**Post date:** [August 1, 2022, 8:35am UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/8 "2022-08-01T08:35:48Z")

</div>

I have exactly the same problem on 24.0.3. The list is more than full (over 12.000 enties) and my Login takes around half a minute. Thanx for posting this solution.  
A proper solution from official side would be even better ;).  
There should be an option for max valid time a session can be valid, without any action. And I tought there is a setting in config.php but even so I set

> ‘session\_lifetime’ =\> 60 \* 60 \* 2,

All sessions stay in the list (including the caldav syncs with my phone).

---

<div class="post-metadata">

**Author:** ![jokabrink](https://help.nextcloud.com/letter_avatar/jokabrink/32/5_5575768a8748004e209b776fc1b2916d.png) [@jokabrink](https://help.nextcloud.com/u/jokabrink)\
**Post date:** [August 8, 2022, 2:33pm UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/9 "2022-08-08T14:33:25Z")

</div>

I stumbled across the same issue. Usually, old tokens get cleaned up in the cron scripts, but currently (NC 24) the cron script does not include the deletion of stale login tokens anymore. The job was called `DefaultTokenCleanupJob`. They removed it (accidentally?) in [this PR](https://github.com/nextcloud/server/pull/30016). It is noted in the [Critical changes for developers and admins for Nextcloud 24](https://github.com/nextcloud/server/issues/29914).

However, they plan to add it back in [Nextcloud 25](https://github.com/nextcloud/server/pull/33375). When added back, the `session_lifetime` should work again.

One can check by logging onto the mariadb/mysql process with the nextcloud credentials, select the nextcloud database, and execute `select * from oc_jobs;`. From there, look for `OC\Authentication\Token\DefaultTokenCleanupJob` and compare the column `last_run` which is the unix timestamp.

---

<div class="post-metadata">

**Author:** ![fluxtop](https://help.nextcloud.com/letter_avatar/fluxtop/32/5_5575768a8748004e209b776fc1b2916d.png) [@fluxtop](https://help.nextcloud.com/u/fluxtop)\
**Post date:** [August 21, 2022, 8:27pm UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/10 "2022-08-21T20:27:35Z")

</div>

Thanks! I can wait until then I hope 🙂

---

<div class="post-metadata">

**Author:** ![woosting](https://help.nextcloud.com/user_avatar/help.nextcloud.com/woosting/32/10424_2.png) [@woosting](https://help.nextcloud.com/u/woosting)\
**Post date:** [June 12, 2023, 12:15am UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/11 "2023-06-12T00:15:49Z")

</div>

I’m still confronted with this issue (more screens than can be loaded).

Anyone had luck removing them (the bash script is scaring me a little…)?

---

<div class="post-metadata">

**Author:** ![wwe](https://help.nextcloud.com/user_avatar/help.nextcloud.com/wwe/32/72963_2.png) [@wwe](https://help.nextcloud.com/u/wwe)\
**Post date:** [December 4, 2024, 7:50am UTC](https://help.nextcloud.com/t/disconnect-all-sessions-revoking-access-for-all-apps-of-a-user/37955/12 "2024-12-04T07:50:28Z")

</div>


