How to use this session timeout guide
Enter the idle timeout, the absolute timeout and whether sliding renewal is on, and the tool reports the worst-case session lifetime and the exposure window if the session is stolen. Add a re-authentication interval and the window is reduced to the shorter of the two, and daily usage gives the number of sign-ins.
How the numbers are derived
With sliding renewal and no absolute timeout the lifetime has no upper bound; with an absolute timeout, that value is the bound. The window for a session left idle is the idle timeout, cut back to the absolute timeout when that is shorter. Sign-ins per day are daily usage divided by the lifetime, rounded down. The OWASP Session Management Cheat Sheet treats the right value as context dependent.
Limits and cautions
No recommended timeout is offered; only the consequences of your settings are calculated. Implementation questions such as whether logout invalidates the session on the server, or where tokens are stored, are out of scope. Real safety has to be judged together with re-authentication and anomaly detection.
Frequently asked questions
An idle timeout counts from the last activity, an absolute timeout from sign-in. With only an idle timeout, a session never ends while an attacker keeps sending requests.
Without an absolute timeout the lifetime has no upper bound. A stolen session also stays alive as long as requests keep arriving.
There is no authoritative value. OWASP treats it as dependent on context and risk, so decide from the exposure windows and your re-authentication points.