Sessions and security
See every device signed in as you — with rough location, browser and last activity — and end any of them immediately.
In this article (4)
Settings → Security lists every session currently signed in as you.
What each row tells you
- The device and browser it was signed in from.
- Its rough location (country, from the network the request came over) — enough to notice something you do not recognise, not a precise position.
- Last activity, so a stale session is obvious.
Ending a session
Sign out on any row ends it immediately — that device has to sign in again. Worth doing after using a shared or borrowed machine, or if a row looks unfamiliar.
Signing out from the account menu ends the session you are using; this page is for all the others.
What to know
- Older sessions may show "Unknown device" if they were created before FlowArray started recording this. They will fill in after a fresh sign-in.
- Access tokens are separate. MCP access tokens and connected assistants are listed and revoked under Settings → MCP access, not here. Signing out a browser session does not revoke a token, and revoking a token does not sign out a browser.
- Share links are separate too — revoke those from the flow's Share dialog.
- Devices that skip your two-factor code are listed here as well — see two-factor sign-in.
If you think something is wrong
Sign out the sessions you do not recognise, change your password, and tell an admin. An admin can also remove a member outright from Members, which ends their access and stops anything unattended they had created.