Skip to main content
Drupal is a registered trademark of Dries Buytaert
Release: Configuration Language Lock 1.0.2 Minor update available for module config_language_lock (1.0.2). Release: Canvas Override 1.0.1 Minor update available for module canvas_override (1.0.1). Release: Media Remote Image 8.x-1.2 Minor update available for module media_entity_remote_image (8.x-1.2). Release: IDNA Convert Service (punycode) 2.0.4 Minor update available for module idna (2.0.4). Release: Bootstrap Cloud 7.1.3 Minor update available for theme bootstrap_cloud (7.1.3). Release: Token Browser 1.0.2 Minor update available for module token_browser (1.0.2). Release: Varbase Project 11.0.8 Minor update available for module varbase_project (11.0.8). Release: Media Remote Image 2.0.0-beta1 First beta version released for module media_entity_remote_image (2.0.0-beta1). Usage Milestone: Term CSV Export Import Module term_csv_export_import crossed 1,000 active installs. Security Coverage: Module Scout Module module_scout now has official Drupal security advisory coverage.

Session Limit

18,932 sites Security covered Drupal 11 · not 10
View on drupal.org

This module limits the number of simultaneous browser sessions a user can have. When a user exceeds their session limit, older sessions are automatically logged out. Administrators can configure this limit and set exceptions for specific roles or users.

Session Limit allows administrators to limit the number of simultaneous sessions per user.

Max session is configurable, no database tables needed.

By default, a session is created for each browser that a user uses to log in. This module will force the user to log out any extra sessions after they exceed the administrator-defined maximum.

Assuming the session limit is 1, if a user is logged in to a Drupal site from their work computer and they log in from their home computer, they would be forced to either log off the work computer session, or abort their new login from home.

Try it out on Simplytest.me

Features

  • On login, logout the oldest session without prompting (optional)
  • At login, prevent login if existing session exists elsewhere (optional)
  • Notify old session about disconnect
  • Configure any number of max allowed sessions
  • Configure session limiting exclusions by role
  • Configure session limiting exclusions by user
  • New user session prompted to select which session to disconnect
  • Implements hook on collision
  • Implements hook on disconnect
  • Implements triggers and compatible with rules
  • Integrates with token module
  • Disregard Masqueraded user sessions in max session counter (optional)

Other recommended modules

  • Autologout - For limiting the length of time a user's session can last (Drupal 7/10).
  • Password Policy - For enforcing password length, complexity and renewal (Drupal 7/10).
  • Ejector seat - For periodically checking if a user has been logged out and then reloading the page they are on so they know they need to login before proceeding (Drupal 7).
  • Warden - For an dashboard overview of the security status of a large estate of Drupal websites (Drupal 7/10).

Depends on

Dependencies of the latest stable release

No dependencies recorded for this project.

Required by

1 tracked project depends on this one

Activity

Tracked releases
6
Tracked since
Jul 2026
Latest release
4 weeks ago
Releases (12 mo)
6 ▲ from 0
Maintenance
Active

Release Timeline

Releases

Version Type Core Release date
3.x-dev Dev 11 Aug 13, 2026
3.0.0 Stable 11 Jul 30, 2026
2.0.3 Stable 10 Jul 30, 2026
3.0.x-dev Dev 11 Jul 27, 2026
3.0.0-beta2 Pre-release 10–11 Jul 27, 2026
3.0.0-beta1 Pre-release 10–11 Jul 27, 2026