Session Duration
Control how long the signed switch cookie remains valid after a session is started.
Navigate to SwitchGuard → Settings → Access Control → Session Duration.
This setting is available in both the free and Pro versions of SwitchGuard. In Pro it works alongside Idle Timeout, which provides an activity-based auto-switch-back on top of the hard expiry set here.
Settings
| Setting | Default | Range | Description |
|---|---|---|---|
| Session Duration | 48 hours | 1–168 hours (up to 7 days) | How long the switchguard_origin cookie stays valid |
How It Works
When a switch session is started, SwitchGuard writes a signed switchguard_origin cookie that stores the original admin's identity. The cookie expiry is calculated from the configured duration at the moment of the switch.
- Browsing activity does not extend the expiry — the clock starts at switch time, not at last activity.
- If the cookie expires before you switch back, the origin identity is forgotten and you must log in to your admin account manually.
- Switch events and the session expiry are both recorded in the Audit Log.
If the session expires while you are browsing as another user, you will be logged in as that user with no automatic switch-back. Log in to your administrator account normally to regain access.
Session Duration vs. Idle Timeout
These two Pro controls are complementary, not duplicates:
| Control | Trigger | Effect |
|---|---|---|
| Session Duration | Time elapsed since switch (regardless of activity) | Cookie expires — origin is forgotten |
| Idle Timeout | No page load for X minutes | Automatic switch-back to original account |
Both can be active at the same time. Example: a 48-hour session duration with a 30-minute idle timeout means:
- The session automatically switches back if you are inactive for 30 minutes.
- Even if you stay active, the hard cookie expiry kicks in after 48 hours.
Recommended Values
| Scenario | Suggested Duration |
|---|---|
| Routine customer support | 48 hours (default) |
| Shared or agency admin accounts | 8–12 hours |
| High-security or compliance environments | 1–4 hours |
| Long development or QA sessions | 72–168 hours |
See Idle Timeout to configure the activity-based complement to this setting.