Session Management and Idle Timeouts
IntermediateControl inactive sessions to limit exposure from unattended workstations and token overhang.
What you'll learn
- FileMaker Server idle timeout for client connections
- Data API token expiration configuration
- WebDirect session timeouts
- Building a custom idle-logout in FileMaker Pro
An authenticated session left open is an open door. FileMaker Server, the Data API, and WebDirect all have configurable session timeout controls. Setting appropriate timeouts is a basic security hygiene measure that limits damage from unattended workstations and leaked tokens.
FileMaker Server client timeout
In Admin Console, Configuration > Client Settings, set the "Disconnect inactive connections after" interval. This disconnects FileMaker Pro and Go clients that have not interacted with the server for the specified time. Default is never. Set it to 60 minutes for most deployments; 15 minutes for high-security environments.
Sign in to track your progress and pick up where you left off.
Sign in to FM Dojo