Changelog

Settings — sign out of all devices

Coach Security settings now includes a "Sign out of all devices" action. Confirming it revokes every refresh token issued to the account, which means every other browser, phone, or tablet is locked out the moment its current access token expires (within an hour by default), and we sign the current browser out immediately.

Until now, the only logout path used scope: 'local', which clears the cookie on the current browser but leaves every other session running. That's not enough for the lost- or shared-device case the DSGVO Art. 32 review flagged.

How to use it:

  1. Coach settings → Security.
  2. Below "Change password", click Sign out everywhere.
  3. Confirm. You'll be redirected to the login screen, and every other session will lose access on its next refresh.

There's still a separate "Log out" in the sidebar — that one only logs out the current device.

Settings — sign out of all devices — Orbi changelog | Orbi