Skip to content
← All patterns

auth

Web Sessions

Who owns this session?

Server-side sessions keyed by token, expired by the database.

A hash-only table where every read is a token lookup. The interesting part is not the read, it is the deletion: a numeric expiresAt attribute hands cleanup to DynamoDB's TTL instead of a sweep job, so the table stays bounded without anyone writing a cron.

The model

Session

A signed-in session, valid until its expiry.

pk
SESSION#<token>

Attributes: userId (S), expiresAt (N), createdAt (N), userAgent (S)

Access patterns

  • GetItemResolve a session token

    Fetch the session behind a token, if it has not expired.

Design notes

TTL is a design here, not a live demonstrationtrade-off

The in-browser engine runs no background expiry, so every seeded session stays in the table and you can read the expired ones. Real DynamoDB deletes them too, but on its own schedule: AWS documents typically within a few days of expiresAt passing, with no guarantee attached. It is background work, not a trigger.

Presence is not validitywhy

Two of the five seeded sessions have passed their expiresAt and are still sitting in the table, because TTL deletion lags. So an application compares expiresAt to the clock rather than treating a row's existence as proof it is still good - a signed-out-by-expiry user whose row has not been swept yet must not be let back in.

Why not delete on sign-outtrade-off

Explicit deletion still makes sense for sign-out, since that is a deliberate act. TTL covers the far commoner case of a session nobody ever closes, which is otherwise a growing table and a write-heavy sweep to keep it in check.

Taught in the course

web-sessionsDynamoDB workbench
Ready to run
Explore an access patternSelect to load & run

Fetch the session behind a token, if it has not expired.

Request
Execute against the local Dynoxide engine
ReturnedFiltered outChanged
PK(pk)
createdAt
expiresAt
userAgent
userId
SESSION#7f3a9c2e
1790553600N
1790640000N
Firefox/desktopS
u-adaS
SESSION#b81d4f6a
1791158400N
1791244800N
Safari/iOSS
u-rajS
SESSION#4e7b1c93
1792540800N
1792627200N
Edge/desktopS
u-samS
SESSION#2c5e8b17
1789776000N
1789862400N
Chrome/desktopS
u-meiS
SESSION#9a0f3d5b
1789516800N
1789603200N
Chrome/AndroidS
u-adaS
Awaiting request
Your next query starts here.

Choose an access pattern above, or build your own request. See what comes back and what it costs.

Write transactions, streams, tags and TTL are among the operations this browser build leaves out. dynoxide's native build has them.