The "Deauthorize session" option does not log out of Bitwarden Desktop when it is not running

I realized that the “Deauthorize Session” option in the web interface doesn’t log me out of Bitwarden Desktop when the desktop application is not running. In fact, it’s still fully functional. This happen on Fedora Workstation 41 with official Bitwarden Desktop from Flathub.

The following is some information about the desktop app I use:

Version 2025.4.2
SDK ‘main (f28b4ef)’
Shell 34.0.0
Renderer 132.0.6834.83
Node 20.18.1
Architecture x64

I cannot reproduce this issue when the Bitwarden desktop application is running, regardless of whether the vault is locked.

Does it remain fully functional even more than an hour after you clicked “deauthorize sessions”?

1 Like

Could you please explain more clearly? How can the desktop app be “fully functional” when it is “not running”?

Sorry for the confusion. What I mean is that if the Bitwarden desktop app is not running when the deauthorization session is initiated, it will still log in when opened.

When you open the desktop app again, does the computer have an internet connection?

FYI, I have been able to reproduce the behavior (in Desktop version 20205.4.2), which appears to be a bug. The same thing is occurring with me for the browser extension (i.e., it remains logged in after deauthorizing all sessions).

Even when the app or extension is force synced, it remains logged in. I believe that the disclaimer about a 1-hour propagation delay is related to the interval of background synchronization, so a forced sync should cause the deauthorization to occur immediately.

FYI, the bug has been reported on Github:

3 Likes