Account
Accounts, identities and sessions
Understand sign-in methods, connected devices and sensitive account changes.
Updated July 19, 2026One user, several verified identities
A SwiftTool user may have a password, Google identity and Telegram identity. Provider tokens are not used as application sessions; SwiftTool creates its own opaque, revocable session after provider verification.
Session lifetime
The default inactivity window is 30 days and an absolute session lifetime also applies. Security events, account status changes and explicit logout can end a session earlier.
- Session tokens are stored in Secure, HttpOnly, SameSite cookies in production.
- Only a SHA-256 hash of the token is stored in MariaDB.
- A session younger than 24 hours cannot disconnect older devices.
Disconnecting Google
A password must exist before Google can be disconnected. The active session must also be at least 24 hours old. These rules prevent an accidental account lockout and reduce the impact of a newly stolen session.