Skip to main content

Sessions and Staying Signed In

A session is the thing that keeps you signed in between page loads. On Onflow Ads a session is held on our servers, not in your browser — your browser only carries a token that points at it. That single design choice is what makes Sign out, a password reset and an account suspension take effect immediately and everywhere, rather than only on the device that asked.

This page collects the rules that are otherwise scattered across the sign-in pages.

How long a session lasts​

How you signed inSession length
Email and password, Remember me unticked48 hours
Email and password, Remember me ticked30 days
Email and password with two-factor — Remember me unticked48 hours
Email and password with two-factor — Remember me ticked30 days
Continue with Google48 hours
Continue with Apple48 hours
Log in with Telegram48 hours
Remember me exists only on the password form

The three provider buttons have no Remember me, so they always give a 48-hour session. If you want the long one, sign in with your email and password and tick the box. An account created through a provider can set a password at any time and then use either route.

When a session expires nothing is lost — the next page you open sends you to the sign-in page, and you carry on where you were.

What ends a session​

EventEffect
Sign outEnds the session on that browser, immediately
Signing in again on the same browserThe previous session on that browser is destroyed and replaced. One browser holds one session
Resetting your passwordDestroys every session on the account, on every device
Sign out other devices on the Security tabDestroys every session except the browser you pressed it in, which carries on under a fresh token
Turning on two-factorSigns every other device out, exactly like Sign out other devices. The browser you turned it on in stays signed in
The team changing your sign-in details — a forced password reset, a sign-in email move, two-factor switched off, or a sign-out of every deviceDestroys every session on the account. You are emailed the reason, and you sign in again when you are ready
An administrator banning or suspending the accountDestroys every session instantly; the next request on any device is signed out
A suspension whose end date has passedThe account reactivates itself on the next sign-in attempt — the old sessions are already gone, so you sign in again
The session lapsing48 hours or 30 days after it was created, as above
Resetting your password signs you out everywhere

This is deliberate. If someone else had a live session on your account, the reset is what kills it — so a password reset is the right first move if you suspect anything, not an inconvenience to be avoided. You will need to sign in again on every device, including the one you reset from.

Two-factor does not shorten your session

Turning two-factor authentication on adds a step to signing in; it does not change how long the session that follows lasts. It does sign your other devices out, because a session somebody else already held would otherwise never meet the new second step.

Where to sign out​

  • The account menu — the avatar in the top navigation, on every page. Sign out is the last item.
  • The Sign out button in the top right of the platform launchpad at /dashboard, and on the engine dashboards.

Both do the same thing. To sign out everywhere else without signing out here, open Account → Security and press Sign out other devices. A notice tells you how many devices were signed out. Signing out always reports success, even if something on our side is having a bad minute — the token is cleared from your browser either way.

The cookies involved​

CookieWhat it is forCan a script read it
onflow_sessionYour session tokenNo — it is HttpOnly
onflow_verifyA verification or password-reset step in progressNo — HttpOnly
onflow_refWhich referral link brought you here, until you sign upNo — HttpOnly
onflow_srcWhich page or campaign first brought you here, so the right one gets the credit if you sign up laterNo — HttpOnly
onflow_pp_sideA first-paint hint about which side of the marketplace you enlisted on, so a channel owner does not see a flash of the advertiser dashboardYes, and it is cleared when you sign out. It is a hint, never authority

All of them are set Secure, so they exist only over HTTPS.

Nothing on the page can see whether you are signed in

Because the session cookie is HttpOnly, no script — ours or anyone else's — can read it. Pages ask the server instead. It is worth knowing when a page seems to think you are signed out: the answer is always a request to our server, so a network stall shows up as a page that greets you as a guest for a second.

What we record about a sign-in​

Every authentication event on your account is logged with the time, the IP address and the browser it came from: sign-ups, sign-ins, failed sign-ins, blocked sign-ins, verifications, password resets, first-email attachments, two-factor being turned on or off, and sign-outs.

If you think someone else has access, reset your password

The log exists for security and abuse investigation, and only our team can read it — so the way to cut someone off is not to hunt for their device but to end every session at once. Sign out other devices on the Security tab ends every session but yours in one press; if the password itself may be known, reset it instead, which ends every session including yours. Then turn on two-factor so a stolen password cannot be used again.

If something goes wrong​

What you seeWhat it meansWhat to do
You are signed out on one device but not anotherYou signed in again somewhere and rotated that browser's session, or the older one lapsedSign in again
Signed out on every device at once, unexpectedlyA password reset or an account suspensionCheck for a confirmation email; if you triggered neither, reset your password immediately
You sign in and are bounced straight back to the sign-in pageThe session cookie is not being stored — most often a browser blocking cookies for the site, or a non-HTTPS addressAllow cookies for onflowads.com and use the https:// address
You are sent to /verify instead of the dashboardYou are signed in, but the email on the account is not verifiedFinish verifying your email
You are sent to /telegram/link instead of the dashboardSigned in and verified, but the account is not connected yetFinish connecting your account
Your account has been suspended. on every routeThe account is banned; every sign-in path checks this before issuing a sessionContact support with your OFA ID
Your account is suspended until [date].A timed suspensionAccess returns by itself after that date — the first sign-in attempt afterwards reactivates the account
A bare Forbidden. page with no explanationYour IP address is blocked at the network layer, before any sign-in is attemptedThis is not about your account. Try another network, and contact support from it