Security
Session lifecycle
Sessions keep you signed in across visits.
Session behavior
- Sessions are stored in cookies.
- Tokens refresh automatically when possible.
- Signing out clears the session.
Cookie workspace selection
Your active workspace and collection are stored in cookies.
What is stored
- currentWorkspaceId
- currentCollectionId
How it is used
- Restores your last selection on next visit.
- Falls back to default collection if needed.
Access removal behavior
When access changes, subsequent protected requests use your updated permissions.
What happens
- Collections you no longer access disappear after refresh.
- The system selects another accessible collection when one exists.
- If your workspace membership is removed, switch to another workspace you can access.
Troubleshooting
Use these fixes when security-related access issues occur.
Session invalid
- Sign in again.
- Clear cookies if the issue persists.
Access revoked
- Contact a workspace owner to restore access.
- Check your invite status.
Workspace not accessible
- Switch to another workspace.
- Sign out and back in.