# `Session` object

The `Session` object is an abstraction over an HTTP session. It models the period of information exchange between a user and the server.

The `Session` object includes methods for recording session activity and ending the session client-side. For security reasons, sessions can also expire server-side.

As soon as a [User](/content/docs/js-frontend/reference/objects/user/index.html) signs in, Clerk creates a `Session` for the current [Client](/content/docs/js-frontend/reference/objects/client/index.html). Clients can have more than one session at any point in time, but only one of those sessions will be **active**.

In certain scenarios, a session might be replaced by another one. This is often the case with [multi-session applications](/content/docs/guides/secure/session-options#multi-session-applications/index.html).

All sessions that are **expired**, **removed**, **replaced**, **ended** or **abandoned** are not considered valid.

Note

For more information regarding the different session states, see the [guide on session management](/content/docs/guides/secure/session-options/index.html).

## [Example](/content/docs/js-frontend/reference/objects/session#example/index.html)

The `Session` object is available on the [Clerk](/content/docs/js-frontend/reference/objects/clerk/index.html) object.

### Example Code

```javascript
import { Clerk } from '@clerk/clerk-js'

const publishableKey = import.meta.env.VITE_CLERK_PUBLISHABLE_KEY

// Initialize Clerk with your Clerk Publishable Key
const clerk = new Clerk(publishableKey)

// Load Clerk
await clerk.load()

// Access the session object
const session = clerk.session
```

## [Properties](/content/docs/js-frontend/reference/objects/session#properties/index.html)

- **Name** `abandonAt`  **Type** `Date`  **Description** The date and time when the session was abandoned by the user.
- **Name** `actor`  **Type** `null | { [x: string]: unknown; sub: string; type?: "agent"; }`  **Description** The JWT actor for the session. Holds identifier for the user that is impersonating the current user. Read more about [impersonation](/content/docs/guides/users/impersonation/index.html).
- **Name** `actor.sub`  **Type** `string`  **Description** The identifier for the user that is impersonating the current user.
- **Name** `actor.type?`  **Type** `"agent"`  **Description** The type of the actor.
- **Name** `agent`  **Type** `null | { [x: string]: unknown; sub: string; type?: "agent"; } & { type: "agent"; }`  **Description** When the session's actor claim has `type: 'agent'`, this property exposes information about the agent and [Agent Task](/content/docs/reference/types/agent-task/index.html) that was used to create the session.
- **Name** `createdAt`  **Type** `Date`  **Description** The date and time when the session was first created.
- **Name** `expireAt`  **Type** `Date`  **Description** The date and time when the session will expire.
- **Name** `id`  **Type** `string`  **Description** The unique identifier for the session.
- **Name** `lastActiveAt`  **Type** `Date`  **Description** The date and time when the session was last active on the [Client](/content/docs/js-frontend/reference/objects/client/index.html).
- **Name** `status`  **Type** [SessionStatus](/content/docs/js-frontend/reference/types/session-status/index.html)  **Description** The current state of the session.

## [Methods](/content/docs/js-frontend/reference/objects/session#methods/index.html)

### [`attemptFirstFactorVerification()`](/content/docs/js-frontend/reference/objects/session#attempt-first-factor-verification/index.html)

Attempts to complete the first factor verification⁠ process.

Returns a [SessionVerification](/content/docs/js-frontend/reference/types/session-verification/index.html) instance with its status and supported factors.

```javascript
function attemptFirstFactorVerification(attemptFactor: SessionVerifyAttemptFirstFactorParams): Promise<SessionVerificationResource>
```

### [`checkAuthorization()`](/content/docs/js-frontend/reference/objects/session#check-authorization/index.html)

Checks if the user is [authorized for the specified Role, Permission, Feature, or Plan](/content/docs/guides/secure/authorization-checks/index.html) or requires the user to [reverify their credentials](/content/docs/guides/secure/reverification/index.html) if their last verification is older than allowed.

```javascript
function checkAuthorization(isAuthorizedParams: CheckAuthorizationParams): boolean
```

### [`clearCache()`](/content/docs/js-frontend/reference/objects/session#clear-cache/index.html)

Clears the cache for the current session. This is useful if the session has been updated and the cache is no longer valid.

```javascript
function clearCache(): void
```

### [`end()`](/content/docs/js-frontend/reference/objects/session#end/index.html)

Marks the session as ended. The session will no longer be active for this `Client` and its status will become **ended**.

```javascript
function end(): Promise<SessionResource>
```

### [`getToken()`](/content/docs/js-frontend/reference/objects/session#get-token/index.html)

Gets the current user's [session token](/content/docs/guides/sessions/session-tokens/index.html) or a [custom JWT template](/content/docs/guides/sessions/jwt-templates/index.html).

### [`verifyWithPasskey()`](/content/docs/js-frontend/reference/objects/session#verify-with-passkey/index.html)

Initiates a verification flow using passkeys.

Returns a [SessionVerification](/content/docs/js-frontend/reference/types/session-verification/index.html) instance with its status and supported factors.

```javascript
function verifyWithPasskey(): Promise<SessionVerificationResource>
```

## Feedback

What did you think of this content?

It's been marked as helpful and up to date.
