Session timeouts

Configure how long users stay logged in.

A session begins when a user logs in to a SnapLogic application and ends when the session times out or the user logs out. When a session expires, the user must log in again. Environment admins can configure session and idle timeouts from the Security section of the left navigation pane:


Admin Manager Session timeout screen

A timeout value can be between 5 and 60 minutes. The default for both values is 60 minutes. The Open Web Application Security Project (OWASP) recommends 2–5 minutes for high-value applications and 15–30 minutes for low-risk applications; since this page's minimum is 5 minutes, use the lowest value the page allows (5 minutes) for high-value applications. Choose a value that balances your security requirements with user productivity.

Enter a value or use the sliders to set:

  • Session timeout: The maximum session duration. The system logs users out this many minutes after login, even if they're actively working. There's no warning before the session ends.
  • Idle timeout: The maximum period of inactivity. The system logs users out after this many minutes without mouse, keyboard, scroll, or touch input.
    • A warning dialog appears 2 minutes before logout, giving users a chance to click Continue to stay logged in. For example, setting Idle timeout to 5 minutes means the dialog appears at 3 minutes of inactivity.
    • Activity in any open SnapLogic tab resets the idle timer.
Important: Set Idle timeout lower than Session timeout. If Idle timeout is greater than or equal to Session timeout, the session timeout is the limiting duration and Idle timeout has no effect.

Click Save to apply your changes.