Everything on this page is opt-in. Nothing changes until you pass the option.
Cookie cache
A signed cookie that answers validateSession without a database read. A revoked session keeps working until the cache expires (5 minutes by default), so keep maxAge short.
The cookie is signed, not encrypted, and tied to the session token it was issued for. Payloads past about 3.6 KB are chunked; oversized ones fall back to database reads.
Refresh token reuse grace
Strict one-time use stays the default. Set reuseGracePeriod (capped at 5 minutes) to tolerate a lost rotation response or two tabs refreshing at once. A token reused inside the window gets a fresh pair; outside it, the whole family is revoked as before.
Per-request base URL
Set allowedHosts (and trustForwardedHeaders only behind a proxy that overwrites the headers) so OAuth redirect URIs follow the request host. Hosts outside the list fall back to baseUrl.
Stateless sessions and federated logout
createStatelessSessions keeps an IdP identity in signed cookies and the IdP tokens in an encrypted cookie, with no database. Sessions cannot be revoked server side, so pair it with isRevoked and createBackChannelLogoutReceiver, which verifies OIDC logout tokens (issuer, audience, jti replay) and calls your onLogout. createEndSessionHandler and buildEndSessionUrl cover RP-initiated logout. Last modified on October 9, 2026