Revoking a session immediately invalidates the session token, effectively logging the user out. Session JWTs are not immediately revoked; they will still validate locally until they hit the 5-minute expiration mark.
We recommend showing users a list of all their active sessions so they can revoke any unrecognized session by IP address or user agent.Use custom claims to attach values to the User Session object via the session_custom_claims parameter.