Skip to content
Skip to main content
Accounts & Identity Technical Explainer

What does logging out actually do?

Logging out usually ends the current account session in one browser or application.

It does not necessarily sign the account out everywhere, remove every token, disconnect every linked application or erase evidence of earlier use.

That is why “the device was logged out” can be much less conclusive than it sounds.

Logout is usually session-specific

A service may log out by:

  • deleting or invalidating a cookie;
  • revoking a session token;
  • marking a server-side session ended; or
  • removing application access.

A separate “log out everywhere” or “revoke all sessions” control may affect more.

Current-session logoutOne browser/app session endsOther active sessions may continue.
Revoke all sessionsProvider invalidates broader accessScope still depends on the service and connected apps.

Closing the browser or app is not necessarily logout either.

Evidence can remain after logout

A logged-out device may still contain:

  • browser history;
  • cached pages;
  • saved usernames;
  • saved passwords;
  • cookies and expired session artefacts;
  • downloaded files;
  • notifications;
  • application databases; and
  • account identifiers.

Those records can still be valuable for reconstructing earlier use.

Old traces do not prove the session was still live

A browser may contain account artefacts long after access ended.

So if continued access matters, compare local material with:

  • provider logout events;
  • session revocation;
  • subsequent requests;
  • security notifications; and
  • other active sessions.

A stale cookie or saved username is not proof that the account remained accessible.

Reconstruct the historical state

Suppose a suspect's laptop is logged out when seized.

That does not tell you whether it was logged in two hours earlier.

The useful question is:

Which session existed at the relevant time, and when did it end?

What is a login session? provides the wider model.

The practical point is: logout changes session access, not the historical evidence. Establish exactly which session ended and when before drawing conclusions from the current screen.

Reference: AI-024Accounts & Identity