SmaiID
V1 · AAL2
SH

Sessions

SmaiID owns the session, not the individual application. Revoking here removes access everywhere in Konsmik.

Active sessions

Each session carries its own assurance level and risk state.

Chrome — WindowsThis device

SES-9F2A · SmaiID · Lagos, NG · Active now

AAL2LOW

WaidesMai — Android

SES-3B71 · WaidesMai · Lagos, NG · 2 hours ago

AAL2LOW

Unknown device — Linux

SES-C40D · WaidTred · Frankfurt, DE · Yesterday

AAL1HIGH

Not yet enforced: Session issuance, refresh rotation and revocation propagation require the SmaiID session service. Revoke controls are disabled in this build.

Session rules

How SmaiID governs a session's life.

  • Sessions are bound to a device and an assurance level.
  • Raising assurance never happens silently — the user sees the step-up.
  • Refresh tokens rotate; reuse of a rotated token revokes the family.
  • Idle and absolute lifetimes are shorter for higher-risk applications.
  • Revocation is authoritative: applications must honour it immediately.

Single sign-on reach

One authentication, many Konsmik surfaces.

  • WaidesMai — communication
  • WaidTred — markets and value transfer
  • Waides Akademi — learning and credentials
  • WaidSoko — commerce
  • KonsDesk — support and operations