-- title: "Logging Out All Devices Did Not Log Them Out: Session Revocation Done Properly" description: "Logging out of all devices clears one kind of credential. Browser sessions, OAuth grants to third party apps and legacy API tokens are three separate things, and access survives as long as any one of them is live. How to tell them apart, the order to revoke in, and what to re-check afterwards." tags: ["security", "privacy", "twitter", "howto"] canonical_url: https://digital-fo...