# Mattermost Desktop: session expired

**URL:** <https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621>\
**Category:** Troubleshooting\
**Created:** [December 12, 2022, 2:12pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621 "2022-12-12T14:12:34Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![montesuma](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/montesuma/32/6176_2.png) [@montesuma](https://forum.mattermost.com/u/montesuma)\
**Post date:** [December 12, 2022, 2:12pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/1 "2022-12-12T14:12:34Z")

</div>

**Summary**  
Every time I open desktop app I receive “Session expired” error. Next, I can successfully login.  
**Steps to reproduce**  
Mattermost Desktop (windows) has version installed (v5.2.1); cleaned the local profile C:\Users\user\AppData\Roaming\Mattermost; revoke all my sessions on the server

1. run Mattermost Desktop
2. query database “SELECT \* FROM sessions WHERE userid=‘my\_user\_id’;” I see my session ID and token my\_session\_token
3. I close the application and see that the session is still present in the database
4. I run Mattermost Desktop again and the application returns an error “session expired”
5. The old session is not picked up by the application; Server logs:  
`{"timestamp":"2022-11-28 08:23:59.742 Z","level":"warn","msg":"Error while creating session for user access token","caller":"app/session.go:89","error":"createSessionForUserAccessToken: Invalid or missing token., resource: UserAccessToken id: token=my_session_token"}`  
`{"timestamp":"2022-11-28 08:23:59.750 Z","level":"warn","msg":"Error while creating session for user access token","caller":"app/session.go:89","error":"createSessionForUserAccessToken: Invalid or missing token., resource: UserAccessToken id: token=my_session_token"}`  
`{"timestamp":"2022-11-28 08:23:59.766 Z","level":"warn","msg":"Error while creating session for user access token","caller":"app/session.go:89","error":"createSessionForUserAccessToken: Invalid or missing token., resource: UserAccessToken id: token=my_session_token"}`  
`{"timestamp":"2022-11-28 08:23:59.774 Z","level":"warn","msg":"Error while creating session for user access token","caller":"app/session.go:89","error":"createSessionForUserAccessToken: Invalid or missing token., resource: UserAccessToken id: token=my_session_token"}`

**Expected behavior**  
No need to login every time open desktop app

Need to notice that a lot of our mattermost users share same ip address. Server deployed using [GitHub - mattermost/docker: Install Mattermost server via Docker](https://github.com/mattermost/docker)  
Server versio 7.2.0-rc3

---

<div class="post-metadata">

**Author:** ![amy.blais](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/amy.blais/32/7481_2.png) [@amy.blais](https://forum.mattermost.com/u/amy.blais)\
**Post date:** [December 12, 2022, 2:52pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/2 "2022-12-12T14:52:36Z")

</div>

Do you see the same issue with desktop app v5.2.2?

---

<div class="post-metadata">

**Author:** ![agriesser](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/agriesser/32/5644_2.png) [@agriesser](https://forum.mattermost.com/u/agriesser)\
**Post date:** [December 12, 2022, 3:16pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/3 "2022-12-12T15:16:06Z")

</div>

Hi montesuma and welcome to the Mattermost forums!

Could it be that you disabled `Personal Access Tokens` in your System Console → Integration Management?

---

<div class="post-metadata">

**Author:** ![montesuma](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/montesuma/32/6176_2.png) [@montesuma](https://forum.mattermost.com/u/montesuma)\
**Post date:** [December 12, 2022, 3:39pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/4 "2022-12-12T15:39:51Z")

</div>

Personal Access Tokens enabled in System Console  
I will try to reproduce with 5.2.2 desktop app

---

<div class="post-metadata">

**Author:** ![montesuma](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/montesuma/32/6176_2.png) [@montesuma](https://forum.mattermost.com/u/montesuma)\
**Post date:** [December 12, 2022, 4:16pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/5 "2022-12-12T16:16:54Z")

</div>

Same issue with 5.2.2

---

<div class="post-metadata">

**Author:** ![agriesser](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/agriesser/32/5644_2.png) [@agriesser](https://forum.mattermost.com/u/agriesser)\
**Post date:** [December 13, 2022, 5:36am UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/6 "2022-12-13T05:36:10Z")

</div>

Alright, next idea: When you’re logged in, click on your profile picture in the top right corner, then on “Profile” and then on “Security” to “View and Log Out of Active Sessions”:

![grafik](https://us1.discourse-cdn.com/flex020/uploads/mattermost/original/2X/f/f6bcf4504624163ec86949ec3071bda8d9042676.png)

 ![grafik](https://us1.discourse-cdn.com/flex020/uploads/mattermost/original/2X/5/562a1b25379e255acb52463db032fdaa4e8bd619.png)

Make sure you log out of all active sessions for your user account, then start a new one and see if this problem still persists. Very unlikely, but maybe one of your sessions is “broken” and therefore causes issues.

---

<div class="post-metadata">

**Author:** ![montesuma](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/montesuma/32/6176_2.png) [@montesuma](https://forum.mattermost.com/u/montesuma)\
**Post date:** [December 13, 2022, 9:02am UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/7 "2022-12-13T09:02:10Z")

</div>

Unfortunately in my environment this issue affect more than one hundred users, so I need to find a root cause. It would be very helpful if you explain how I can identify “broken” session in more technical terms, may be something on database level

---

<div class="post-metadata">

**Author:** ![agriesser](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/agriesser/32/5644_2.png) [@agriesser](https://forum.mattermost.com/u/agriesser)\
**Post date:** [December 13, 2022, 10:54am UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/8 "2022-12-13T10:54:13Z")

</div>

I don’t know how to identify them, it was just an assumption that maybe one of the sessions is corrupt and I wanted to find out if the problem gets fixed when you clear your user’s sessions manually using the GUI and if there are any sessions left.

You can export the sessions in your database first by running the following query:

```sql
select * from sessions where userid IN (SELECT id FROM users where username='YOURNAME');

```

The values for the column `expiresat` would be interesting, they should contain a unix timestamp which should be resonably higher than the `createat` timestamp.

```sql
mattermost=# SELECT TO_TIMESTAMP(createat/1000),TO_TIMESTAMP(expiresat/1000) from sessions where userid IN (SELECT id FROM users where username='YOURNAME');
      to_timestamp | to_timestamp
------------------------+------------------------
 2022-10-27 07:31:15+02 | 2022-12-16 10:43:01+01
 2022-12-08 17:26:13+01 | 2022-12-27 05:41:46+01
 2022-12-02 14:47:11+01 | 2022-12-21 07:41:45+01
 2022-08-24 16:52:03+02 | 2022-12-27 09:08:06+01
(4 rows)

```

There are several settings in the system console and `config.json` that have an impact on the session duration, here’s an example out of my `config.json`:

```auto
# grep SessionLength /opt/mattermost/config/config.json
        "ExtendSessionLengthWithActivity": true,
        "SessionLengthWebInDays": 14,
        "SessionLengthWebInHours": 336,
        "SessionLengthMobileInDays": 14,
        "SessionLengthMobileInHours": 336,
        "SessionLengthSSOInDays": 14,
        "SessionLengthSSOInHours": 336,

```

The values here mean that I do have 14d session length, so users would have to re-login after 14 days and additionally, I do extend the session expiration when there’s activity on the account (`ExtendSessionLengthWithActivity`).

What do these values look like on your system?

---

<div class="post-metadata">

**Author:** ![montesuma](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/montesuma/32/6176_2.png) [@montesuma](https://forum.mattermost.com/u/montesuma)\
**Post date:** [December 22, 2022, 2:26pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/9 "2022-12-22T14:26:16Z")

</div>

> [@agriesser](#):
>
> `grep SessionLength /opt/mattermost/config/config.json`

```auto
        "ExtendSessionLengthWithActivity": true,
        "SessionLengthWebInDays": 180,
        "SessionLengthWebInHours": 4320,
        "SessionLengthMobileInDays": 180,
        "SessionLengthMobileInHours": 4320,
        "SessionLengthSSOInDays": 30,
        "SessionLengthSSOInHours": 720,

```

---

<div class="post-metadata">

**Author:** ![agriesser](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/agriesser/32/5644_2.png) [@agriesser](https://forum.mattermost.com/u/agriesser)\
**Post date:** [December 31, 2022, 4:03pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/10 "2022-12-31T16:03:02Z")

</div>

OK, one last guess here - can you please confirm that the URL you’re using to connect to your Mattermost server in the desktop app matches the `SiteUrl` setting in your system console (section “Environment” → “Web Server”)? The newer desktop app clients automatically redirect to the value provided in the server`s `SiteURL` and maybe that’s causing the logout for you.

---

<div class="post-metadata">

**Author:** ![montesuma](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/montesuma/32/6176_2.png) [@montesuma](https://forum.mattermost.com/u/montesuma)\
**Post date:** [January 9, 2023, 2:48pm UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/11 "2023-01-09T14:48:49Z")

</div>

I have checked settings, both URLs match

---

<div class="post-metadata">

**Author:** ![agriesser](https://sea2.discourse-cdn.com/flex020/user_avatar/forum.mattermost.com/agriesser/32/5644_2.png) [@agriesser](https://forum.mattermost.com/u/agriesser)\
**Post date:** [January 23, 2023, 4:49am UTC](https://forum.mattermost.com/t/mattermost-desktop-session-expired/14621/12 "2023-01-23T04:49:13Z")

</div>

Hi montesuma,

in a different thread, someone pointed out that their reverse proxy was tinkering with the headers and caused the initial authentication header the client sends to the Mattermost server to be dropped and therefore the sessions had to be recreated everytime they started the application.  
Can you please describe your server side setup a bit more? Do you use a reverse proxy in front of your Mattermost server and if so, what does its configuration look like? Are you working on some of the request headers in there in order to modify the loadbalancing algorithm or anything like that?
