What is Front-channel logout?
OpenID Connect Front-Channel Logout uses the user's browser to load each registered relying party logout URI, normally in an iframe rendered by the OpenID Provider. The relying party clears browser session state for the logout request. The provider may include iss and sid together so the relying party can match a specific session. Browser privacy controls, network failures, or blocked third-party content can prevent delivery, so front-channel logout cannot guarantee that every session ends at once.
Why it matters
Single sign-on can create sessions at several relying parties. Front-channel logout lets one browser-based sign-out event ask those relying parties to clear their local sessions.
How it works
- The OpenID Provider finds the relying parties that participate in the user's login session.
- The provider returns a browser page that loads each registered front-channel logout URI, normally in an iframe. It may add issuer and session data.
- Each relying party clears its browser session state and may verify and use the issuer and session identifier when both are present.
Example
A user signs out at the identity provider. The returned page loads logout URIs for the support and payroll applications, and each application clears its local session.
Pomerium boundary
Pomerium supports OpenID Connect Front-Channel Logout. Register the protected route plus /.pomerium/sign_out as the front-channel logout URI so Pomerium can clear its local session during single sign-out.
Limits and non-claims
- Browser privacy controls or blocked third-party content can stop an iframe request.
- The OpenID Provider does not receive a reliable success response from each relying party.
- Clearing a browser session does not by itself revoke access tokens or stop a separate API session.
Evaluation checklist
- Which browser requests reach each relying party, and which local sessions do they select?
- How does each relying party correlate the issuer, subject, and session identifier?
- What ends stale sessions when a browser blocks, misses, or abandons logout delivery?
