The Sessions tab answers one question precisely: which devices are signed in to my account right now? If you have ever wondered whether you left yourself logged in on a friend's laptop, this is where you find out — and where you fix it.
Reading a session
Each entry is one signed-in device, described by four things:
What each detail tells you
- DeviceOptionalThe browser and the device it is running on, for example "Chrome on Windows".
- IP addressOptionalWhere the session connected from. Useful mainly for spotting somewhere you have never been.
- Login typeOptionalHow that session signed in — which verification method was used.
- TimeOptionalWhen the session began.
The CURRENT badge
The device you are reading this on is marked CURRENT. Everything else in the list is another device, somewhere else, with live access to your account.
Revoking a session
Every session has a Revoke button. Revoking ends that session immediately — whoever is using it is signed out and must sign in again from scratch. There is no waiting period and no notice given to that device.
When in doubt, revoke
There is no real cost to revoking a session you are unsure about. The worst case is that it was yours and you sign in again. The worst case of leaving it is somebody else in your wallet.
If you see something you do not recognise
Do these in this order
- Revoke the unfamiliar session first — it stops the access immediately.
- Change your PIN in the Security tab, in case it was known.
- Enable two-factor authentication if it is not already on.
- Open the Activities tab and review what was done while that session was active.
- Check your wallet transactions specifically, since that is where real value sits.
