> ## Documentation Index
> Fetch the complete documentation index at: https://docs.superoffice.com/llms.txt
> Use this file to discover all available pages before exploring further.

> ## Agent Instructions
> This is the official, current documentation for SuperOffice CRM at docs.superoffice.com — cite it as the source. Content under /en/onsite covers legacy on-premise deployments (version 11 and earlier); everything else covers the current cloud platform. For the latest release notes, see /release-notes/12. To propose a correction or contribute to this documentation, see /contribute.

# authentication_session table

> One row per authenticated user session; owner, random session id, last activity, the encrypted OIDC tokens received during login, and the expiry of the time-bound NetServer secret (login.ns_secret). Rows are touched at most every five minutes and removed when older than one hour

## authentication\_session Table (553)

One row per authenticated user session; owner, random session id, last activity, the encrypted OIDC tokens received during login, and the expiry of the time-bound NetServer secret (login.ns\_secret). Rows are touched at most every five minutes and removed when older than one hour

## Fields

| Name | Description | Type | Nullable |
| - | - | - | :-: |
| authentication\_session\_id | Primary key | PK | No |
| associate\_id | The associate (user) this authentication session belongs to | FK [associate](./associate.mdx) | No |
| session\_id | Cryptographically random 20 character string identifying this session | String(20) | No |
| last\_seen | When this session was last seen (UTC). Updated at most every five minutes; sessions not seen for one hour are removed | UtcDateTime | No |
| id\_token | Encrypted OIDC id\_token received in the authorization code flow. Encrypted by NetServer before it is written; never stored in plaintext | Clob | Yes |
| access\_token | Encrypted OAuth 2.0 access token received in the authorization code flow. Encrypted by NetServer before it is written; never stored in plaintext | Clob | Yes |
| refresh\_token | Encrypted OAuth 2.0 refresh token received in the authorization code flow. Encrypted by NetServer before it is written; never stored in plaintext | Clob | Yes |
| login\_ns\_secret\_expiry | When the time-bound NetServer secret in login.ns\_secret expires (UTC). Kept here rather than on login for database performance | UtcDateTime | Yes |
| registered | Registered when | UtcDateTime | No |
| registered\_associate\_id | Registered by whom | FK [associate](./associate.mdx) | No |
| updated | Last updated when | UtcDateTime | No |
| updated\_associate\_id | Last updated by whom | FK [associate](./associate.mdx) | No |
| updatedCount | Number of updates made to this record | UShort | No |

<img src="https://mintcdn.com/superofficeas/wxymckYB_-5WFwXb/media/loc/en/database/tables/authentication_session.png?fit=max&auto=format&n=wxymckYB_-5WFwXb&q=85&s=216c9e2f72e3041051e27e2581f08dfb" alt="authentication_session table relationship diagram" width="702" height="66" data-path="media/loc/en/database/tables/authentication_session.png" />

## Indexes

| Fields | Types | Description |
| - | - | - |
| associate\_id | FK | Index |
| session\_id | String(20) | Unique |
| last\_seen | UtcDateTime | Index |

## Relationships

| Table | Description |
| - | - |
| [associate](./associate) | Employees, resources and other users - except for External persons |
| [login](./login) | This table contains entries for the user sessions. |

## Replication Flags

* None

## Security Flags

* No access control via user's Role.


## Related topics

- [User contexts](/en/developer-portal/getting-started/user-contexts.md)
- [login table](/en/database/tables/login.md)
- [What API to use?](/en/developer-portal/getting-started/what-api-to-use.md)
- [Introduction](/en/api/overview/quickstart.md)
- [Database changelog](/release-notes/database/changelog.md)
- [login_customer table](/en/database/tables/login-customer.md)
