How to Log Out of Twitter
Signing out on web, iOS and Android, and how to end sessions on devices you no longer have in front of you.
Desktop logout path
In x.com in a desktop browser, the logout control is hidden under More on the left sidebar. Select More at the base of the route section and afterward select Log out. A confirmation dialog appears. You confirm it and the session is closed as of that point — on the current browser. Two tap path is sufficient only if you want this tab signed out. You reach that same More menu if you've already been in Settings. Do not hunt in the top bar. In the wide version, and you left column that control remains.
Then open the accounts switcher at the bottom of the left sidebar if several accounts are input to this same browser instead of More. The switcher shows each signed in handle. Instead choose Log out of all accounts and this will terminate the entire browser session with one click. So that clears all handles that where sitting in that profile. When you verify, the page will navigate back to login screen Then, on a machine you do not own, after logging out follow up with wiping x.com cookies so that an old session cookie can not reopened the timeline without the correct password.
Phone logout path
On the official iPhone or Android app, tap your profile picture in the top left corner to open up the side drawer. Then tap on Settings and privacy Scroll to the bottom of that screen and tap Log out and then confirm. Some builds replace Log out with account switcher instead. From there you tap on the account name at the top of the drawer and find Log out in the list. Either route does not end every session on that phone. Other devices remain signed in until you sign them out later from the sessions screen.
When multiple accounts are logged into the same app all have to log off out of it separately unless you choose log out of all when prompted. Tapping Log out causes the app to return to that handle's login screen. The others handles stay in the switcher until you do that one more time. When you log out from the app -- web sessions / another phone is untouched. Phone logout should be considered local only. If it is someone else list the account on the switcher so they can't tap in.
Shared computer cleanup
So when you log out on a public or shared computer the session cookie can still sit in the browser. Go to the browser settings -> Cookies and site data, and delete all stored files for x.com and twitter. com. In Chrome that is Settings -> Privacy and security -> Cookies -> See all site data → then search x.com and delete. In Firefox it is Setting Privacy Cookies Manage Data. For Safari Settings Privacy Manage Website Data. Some cookies can restore the timeline without inputting a password until those cookies are gone to a later visitor
You should close also your every tab which exists on x.com before walk. An open tab that has not been refreshed can retain the page in memory after cookies have been cleared. Select a private window to begin with, on a library or cafe machine so that nothing is written to disk. The closing together with the cookie-wipe from a normal window means you've already used a normal window, but you can wipe this pair enables access ends. Avoid just using the Log out button on hardware that you do not own.
Remote session revocation
The valuable path for a security mind-set is signing out devices you no longer have. Go to Settings and privacy then Security and account access then Apps and sessions Sessions lists all devices that are signed in live. Each row indicates an approximate location and when the phone was last active so you can differentiate a phone that you sold between the one in your pocket. After that, tap or click on a session that you do not recognise and revoke it. That kill is immediate. You remain logged in on this device.
The same Apps and sessions screen is where you see Sessions for the web, the iOS app, the Android app or any other client that used your password or a saved token. Live last active times that are months-old, still counts alive until you revoke. Instead, a laptop that you wiped last year can still hold a valid cookie. Go through every line. If the place is a city you do not visited, turn it off even if timestamps appear long time ago. And one last session for someone else to post.
Connected app revocation
Open Connected apps on the same Security and account access screen. This list is of every third party service you've ever authorized to read or write with your account. Old tokens continue to function long after you mop up the app. Revoke anything that you do not use anymore They revoke the validity of that token in one go. A neglected analytics dashboard or a rotative cross poster will also be able to read your DMs or publish, if his token is still alive. Process the list just like you would Sessions. You never leave a name without some explanation.
Removing a connected app does not sign you out of the official X apps or site. It simply cuts that third party. If you are performing a cleanup after an incident, then resync Connected apps only after changing the password, since an attacker can just refresh the previously stolen token. A few applications will prompt you to authorise once more the following time you dispatch them. That is expected. Only re-authorise what you are actively using this week. If you have an old account this list can be long. Scroll to the end.
Compromised account steps
If you suspect someone else got in, then the first step is to change the password. Changing your password log out of other sessions and is the quickest way to drop unknown devices. In the security section, locate password change through Settings and privacy. Choose a password you do not use elsewhere. Return to Apps and sessions after making the switch, and revoke anything that is still listed. Now switch on two factor authentication from the same Security menu so that next time a stolen password will not be sufficient. Complete the password before revoking better apps.
Then follow with your own timeline. Delete anything that was posted in your name while your account is compromised. Typically, you give it away with a flurry of spam or reponds that are not your own. If the intrusion generated a run of posts that you want exterminated, then TweetSweep can obliterate a date range with one swipe. Let your start and end date be the window you were locked out, and run the delete. Then, examine DM's and lists too. But you have half-finished until that content is no longer available and then you log out everywhere.