Session control
The console lists the sessions your users hold on a custom login domain and revokes any one of them. A sign-in that holds tokens ends when its refresh token is revoked, when you disable the app, or when the tokens expire.
The session list
Each sign-in app has a list of its active sessions in the console, on the app's custom domains page. A row shows the user's id, how they signed in and when the session was last seen, with a Revoke button beside it. Listing needs the users:read permission and revoking needs users:write. The list is kept per app, and a user's own page carries no list of their sessions.
Which sign-ins appear
A session of this kind exists only for a sign-in completed on a verified custom login domain. A sign-in on Fóir's default domain, or through the token API, issues tokens and creates no session, so it never appears in the list.
What revoking does
Revoking a session signs that user out, and their app can no longer mint an access token from it. The revoke fires a SESSION_REVOKED event in the same transaction, carrying the session and user ids, so your own systems can drop what they cached. The same event fires when a user signs out and when an app is disabled.
Ending other sign-ins
A user's own sign-out ends their session on the login domain. For a token sign-in, posting the refresh token to the revoke endpoint ends that token family. Disabling a sign-in app ends all of its users' sessions and tokens at once, and the API stops honouring its access tokens without waiting for them to expire. A password reset ends that user's sessions and refresh tokens.
Lifetimes
An access token lasts 15 minutes, and a refresh token lasts 30 days and rotates on every use. A session ends after 30 days without use or 90 days after first sign-in, and both windows can be set per project.
Read the detail
The sign-in guide covers session windows, sign-out and token lifetimes, and the console's session list has no documentation page of its own.