> For the complete documentation index, see [llms.txt](https://developer.harness.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://developer.harness.io/web-application-and-api-protection-waap/settings/configuration/session-configuration.md).

# Session Configuration

Traceable allows you to define the maximum duration for both active and idle sessions, after which the users are logged out of their Traceable account. This helps you decide how and when users are logged out, keeping access secure while maintaining flexibility for your team.

### What will you learn in this topic?

By the end of this topic, you will be able to:

* Understand the steps to define the maximum durations for active and idle sessions after which the users will be logged out of a session in Traceable.

***

### Session configuration steps

To configure the session, log in to your Traceable account and complete the following steps:

1. Navigate to **Settings**.
2. Under **Configuration**, click **Session Configuration**.
3. Define the **Maximum Session Duration** using the **Days, Hours**, and **Minutes** drop-down to set how long a user can stay logged in, regardless of activity. For example, *7* days.

   <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p>Traceable allows you to set the maximum session duration to <em>seven</em> days regardless of activity.</p></div>
4. Define the **Idle Session Duration** using the **Days**, **Hours**, and **Minutes** drop-down to set how long a user can remain inactive before being logged out. For example, *3* days.

<figure><img src="/files/KG9y4bQw6Ptv7DSxHE3o" alt=""><figcaption><p>Session Configuration</p></figcaption></figure>

After configuring these, the user is automatically logged out after the maximum session duration, regardless of activity. Moreover, if no activity is detected, users are logged out after crossing the idle session duration limit.
