Sessions and Staying Signed In
A session is the thing that keeps you signed in between page loads. On Onflow Ads a session is held on our servers, not in your browser — your browser only carries a token that points at it. That single design choice is what makes Sign out, a password reset and an account suspension take effect immediately and everywhere, rather than only on the device that asked.
This page collects the rules that are otherwise scattered across the sign-in pages.
How long a session lasts​
| How you signed in | Session length |
|---|---|
| Email and password, Remember me unticked | 48 hours |
| Email and password, Remember me ticked | 30 days |
| Email and password with two-factor — Remember me unticked | 48 hours |
| Email and password with two-factor — Remember me ticked | 30 days |
| Continue with Google | 48 hours |
| Continue with Apple | 48 hours |
| Log in with Telegram | 48 hours |
The three provider buttons have no Remember me, so they always give a 48-hour session. If you want the long one, sign in with your email and password and tick the box. An account created through a provider can set a password at any time and then use either route.
When a session expires nothing is lost — the next page you open sends you to the sign-in page, and you carry on where you were.
What ends a session​
| Event | Effect |
|---|---|
| Sign out | Ends the session on that browser, immediately |
| Signing in again on the same browser | The previous session on that browser is destroyed and replaced. One browser holds one session |
| Resetting your password | Destroys every session on the account, on every device |
| Sign out other devices on the Security tab | Destroys every session except the browser you pressed it in, which carries on under a fresh token |
| Turning on two-factor | Signs every other device out, exactly like Sign out other devices. The browser you turned it on in stays signed in |
| The team changing your sign-in details — a forced password reset, a sign-in email move, two-factor switched off, or a sign-out of every device | Destroys every session on the account. You are emailed the reason, and you sign in again when you are ready |
| An administrator banning or suspending the account | Destroys every session instantly; the next request on any device is signed out |
| A suspension whose end date has passed | The account reactivates itself on the next sign-in attempt — the old sessions are already gone, so you sign in again |
| The session lapsing | 48 hours or 30 days after it was created, as above |
This is deliberate. If someone else had a live session on your account, the reset is what kills it — so a password reset is the right first move if you suspect anything, not an inconvenience to be avoided. You will need to sign in again on every device, including the one you reset from.
Turning two-factor authentication on adds a step to signing in; it does not change how long the session that follows lasts. It does sign your other devices out, because a session somebody else already held would otherwise never meet the new second step.
Where to sign out​
- The account menu — the avatar in the top navigation, on every page. Sign out is the last item.
- The Sign out button in the top right of the platform launchpad at
/dashboard, and on the engine dashboards.
Both do the same thing. To sign out everywhere else without signing out here, open Account → Security and press Sign out other devices. A notice tells you how many devices were signed out. Signing out always reports success, even if something on our side is having a bad minute — the token is cleared from your browser either way.
The cookies involved​
| Cookie | What it is for | Can a script read it |
|---|---|---|
onflow_session | Your session token | No — it is HttpOnly |
onflow_verify | A verification or password-reset step in progress | No — HttpOnly |
onflow_ref | Which referral link brought you here, until you sign up | No — HttpOnly |
onflow_src | Which page or campaign first brought you here, so the right one gets the credit if you sign up later | No — HttpOnly |
onflow_pp_side | A first-paint hint about which side of the marketplace you enlisted on, so a channel owner does not see a flash of the advertiser dashboard | Yes, and it is cleared when you sign out. It is a hint, never authority |
All of them are set Secure, so they exist only over HTTPS.
Because the session cookie is HttpOnly, no script — ours or anyone else's — can read it. Pages ask the server instead. It is worth knowing when a page seems to think you are signed out: the answer is always a request to our server, so a network stall shows up as a page that greets you as a guest for a second.
What we record about a sign-in​
Every authentication event on your account is logged with the time, the IP address and the browser it came from: sign-ups, sign-ins, failed sign-ins, blocked sign-ins, verifications, password resets, first-email attachments, two-factor being turned on or off, and sign-outs.
The log exists for security and abuse investigation, and only our team can read it — so the way to cut someone off is not to hunt for their device but to end every session at once. Sign out other devices on the Security tab ends every session but yours in one press; if the password itself may be known, reset it instead, which ends every session including yours. Then turn on two-factor so a stolen password cannot be used again.
If something goes wrong​
| What you see | What it means | What to do |
|---|---|---|
| You are signed out on one device but not another | You signed in again somewhere and rotated that browser's session, or the older one lapsed | Sign in again |
| Signed out on every device at once, unexpectedly | A password reset or an account suspension | Check for a confirmation email; if you triggered neither, reset your password immediately |
| You sign in and are bounced straight back to the sign-in page | The session cookie is not being stored — most often a browser blocking cookies for the site, or a non-HTTPS address | Allow cookies for onflowads.com and use the https:// address |
You are sent to /verify instead of the dashboard | You are signed in, but the email on the account is not verified | Finish verifying your email |
You are sent to /telegram/link instead of the dashboard | Signed in and verified, but the account is not connected yet | Finish connecting your account |
| Your account has been suspended. on every route | The account is banned; every sign-in path checks this before issuing a session | Contact support with your OFA ID |
| Your account is suspended until [date]. | A timed suspension | Access returns by itself after that date — the first sign-in attempt afterwards reactivates the account |
| A bare Forbidden. page with no explanation | Your IP address is blocked at the network layer, before any sign-in is attempted | This is not about your account. Try another network, and contact support from it |
Related​
- Signing in with email — the Remember me checkbox and every sign-in message.
- Resetting your password — the one action that ends every session.
- Two-factor authentication — the second lock in front of a new session.
- Limits and lockouts — what happens when you try too often.