Join our Newsletter — 33% off our NHI Course
Home› Glossary› Authentication, Authorisation & Trust› Application Session
Authentication, Authorisation & Trust

Application Session

← Back to Glossary
By NHI Mgmt Group Updated October 6, 2026 Domain: Authentication, Authorisation & Trust

An application session is the period during which the app treats a user as authenticated and allowed to act. The session may outlive the original login event, so its lifetime, termination rules and re-authentication triggers must be governed explicitly.

What an application session represents

An application session is the live authorization state an app maintains after login, letting a user continue acting without repeating the original authentication step on every request. It is a practical bridge between identity proof and ongoing access.

The important distinction is that the session is not the login itself. Login proves the user once; the session governs what happens next, including how long that trust lasts and what conditions force it to end or be renewed.

How session lifetime and state work

Sessions can be short-lived or persist for longer periods depending on the application’s design, the risk of the action being performed, and the strength of the authentication used to create the session. During that period, the app typically tracks a session identifier, cookie, token, or similar state so it can recognize the user across multiple interactions.

Session state is what makes workflows usable, but it also creates a trust window. If the session lasts too long, is not bound tightly enough to the right context, or survives after the user should no longer be considered trusted, the app can end up granting access beyond the intended point.

Termination, renewal, and re-authentication

Good session handling defines when the session expires, when inactivity should end it, when sensitive actions should require re-authentication, and when a user should be forced to log in again after risk-relevant events such as password changes or device changes. Those rules are part of access control, not just user experience.

Applications also need to decide whether to use absolute expiration, idle timeout, or both. Absolute expiration limits the total lifetime of a session, while idle timeout limits how long a dormant session stays usable. Re-authentication triggers reduce the chance that a stale or hijacked session can be used for high-impact actions.

Why application sessions matter to security

Because a valid session often confers the same authority as the logged-in user, session compromise can become direct account abuse. A stolen session may let an attacker bypass the login step entirely, which is why session design sits close to authentication, authorization, and account protection.

Session security is especially important for web applications and APIs where tokens, cookies, and browser state can be reused across requests. The session boundary is often where application security succeeds or fails in practice, because it determines whether an authenticated state remains trustworthy over time.

Risk and Threat Considerations

Application sessions create a valuable reuse window for attackers because they can preserve authenticated access even after the original login event is over. If session identifiers are stolen, replayed, or left valid for too long, the attacker may act as the user without needing credentials again.

Failure mechanism: The session remains valid after compromise, is not sufficiently tied to the client context, or is not invalidated when risk changes, allowing unauthorized continuation of the trusted state.

Impact: Account takeover, unauthorized transactions, data exposure, and persistent abuse of application functions can follow, especially where high-value actions do not force fresh authentication.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP ASVS, NIST SP 800-53 Rev 5, NIST SP 800-63 and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
OWASP ASVSV6 — AuthenticationSession state depends on authentication and re-authentication behavior.
V7 — Session ManagementApplication sessions are governed by ASVS session lifecycle and invalidation expectations.
V8 — AuthorizationA session carries the user's active authorization to act within the app.
Recommendation — Define when authentication must be renewed before restoring sensitive access. Enforce secure session creation, expiration, renewal, and invalidation rules. Re-check authorization for sensitive actions during an active session.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementSession longevity and renewal depend on controlled authenticator and token handling.
AC-12 — Session TerminationThis control directly governs ending inactive or terminated sessions.
AC-7 — Unsuccessful Logon AttemptsSession controls often complement re-authentication and lockout behavior after risk events.
Recommendation — Manage session-related authenticators so they expire and rotate appropriately. Terminate idle or ended sessions promptly to limit unauthorized reuse. Pair session renewal rules with lockout and re-authentication thresholds.
NIST SP 800-63AAL — Authenticator Assurance LevelSession lifetime and reauthentication depend on the assurance level of the original login.
Recommendation — Match session duration and step-up checks to the assurance level in use.
CIS Controls v85 — Account ManagementSession lifecycle depends on active account handling and timely removal of access.
Recommendation — Remove or disable access paths that should no longer support active sessions.

Practitioner Guidance

What to watch for: Treat sessions as governed security state, not just convenience state. The most important decisions are how a session is created, how long it remains valid, and which actions should force renewal or re-authentication.

Practitioner takeaway: A session should last only as long as the application can reasonably continue trusting that user context, and no longer.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 6, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org