RP-Initiated Logout
RP-Initiated Logout is an OpenID Connect extension that lets a relying party (the client) end a user's session at the authorization server — as opposed to revoke(), which only invalidates a specific token. It's implemented by SessionLogoutFlow in this SDK.
The flow works by redirecting the user's browser to the authorization server's end_session_endpoint, passing along the ID token being signed out of (as proof of the session to end) and an optional URL to return to once logout completes.
TIP
SessionLogoutFlow only builds this redirect URL — it doesn't revoke any tokens itself. Whether the authorization server's end_session_endpoint invalidates the underlying tokens server-side is IDP-dependent. To explicitly invalidate a token, use Credential.revoke() from @okta/auth-foundation.
Participants
- Resource Owner: the user signing out
- Relying Party: your application
- Authorization Server / Identity Provider: owns the session being terminated
How It Works
- The client resolves the ID token for the session being ended and generates a
statevalue. - The client redirects the user's browser to the authorization server's
end_session_endpoint, includingid_token_hint,post_logout_redirect_uri, andstate. - The authorization server validates the
id_token_hintand terminates the session it represents at the IDP. - The authorization server redirects the browser back to
post_logout_redirect_uriwith the originalstate. - The client verifies the returned
statematches what it sent in step 1. - The client removes its own local credential (see Managing User Credentials), since RP-Initiated Logout only ends the IDP session — it doesn't clear anything the client itself persisted.
Security Considerations
statemust be unique per logout request and verified on redirect, the same protection it provides during Authorization Code Flow.id_token_hintmust be a token previously issued to this client — an authorization server should refuse to end a session on behalf of an arbitrary/unrelated ID token.post_logout_redirect_urishould be validated by the authorization server against a pre-registered allowlist, the same wayredirect_uriis validated during sign-in, to prevent an attacker from redirecting a signed-out user somewhere unexpected.- Ending the IDP session doesn't retroactively invalidate tokens already issued for it. If tokens need to stop working immediately, revoke them explicitly with
Credential.revoke()in addition to running this flow. - It's recommended to make a
POSTrequest to theend_session_endpointinstead ofGET. In aGETrequest, the ID token will be exposed as a query parameter (viaid_token_hint). APOSTrequest does not have the same concern since the request body is hidden.
NOTE
In Single Sign-On scenarios, ending the IDP session may sign the user out of every application sharing that session — not just this one. See Managing User Credentials for guidance on when SessionLogoutFlow is (and isn't) the right tool.
See Also
- Okta Documentation: API Reference
- OpenID Connect RP-Initiated Logout 1.0