> Markdown version of [Add Logout](https://vaadin.com/docs/next/building-apps/security/add-logout). Section index: [llms.txt](https://vaadin.com/docs/next/building-apps/llms.txt)

# Add Logout

Logging out of an application is just as important as logging in. Leaving a session open for too long or failing to properly close it can lead to serious security risks.

Since Vaadin uses **Spring Security** for authentication, it also relies on it for **logging out and session invalidation**.

> **Important: Vaadin Logout vs. Spring Logout**
>
> In a traditional Spring web application, logging out requires sending a `POST` request to `/logout`, which must include Spring’s CSRF token. However, Vaadin applications use their own CSRF protection mechanism, making this approach difficult to implement. Additionally, since Vaadin views run on the server, they don’t interact with HTTP requests directly.

## <a id="logging-out"></a>Logging Out

Vaadin provides the class `AuthenticationContext`, which includes a `logout()` method. Calling this method **logs out the user** and **redirects** them to a preconfigured **logout success URL**.

You typically call `logout()` from a **button** or **menu item** click listener. Here’s how to add a logout button to a view:

```java
import com.vaadin.flow.spring.security.AuthenticationContext;
import jakarta.annotation.security.PermitAll;

@Route("account")
@PermitAll // (1)
public class AccountView extends Main {

    public AccountView(AuthenticationContext authenticationContext) { // (2)
        add(new Button("Logout", event -> authenticationContext.logout()));
    }
}
```

1. Grants access to *authenticated users* — otherwise, users wouldn’t be able to log out.

2. Injects `AuthenticationContext`, which is a Spring Bean.

## <a id="configuring-the-logout-success-url"></a>Configuring the Logout Success URL

By default, users are redirected to the root URL (`/`) after logging out. To change this, **specify a custom logout success URL** in your security configuration:

`SecurityConfig.java`

```java
@EnableWebSecurity
@Configuration
class SecurityConfig {

    @Bean
    SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
// tag::snippet[]
        http.authorizeHttpRequests(auth -> auth
                .requestMatchers("/logged-out.html").permitAll()); // (1)
// end::snippet[]
        // Configure Vaadin's security using VaadinSecurityConfigurer
        http.with(VaadinSecurityConfigurer.vaadin(), configurer -> {
// tag::snippet[]
            configurer.loginView(LoginView.class, "/logged-out.html"); // (2)
// end::snippet[]
        });
        return http.build();
    }
    ...
}
```

1. Lets anyone access `/logged-out.html`.

2. Sets `/logged-out.html` as the **logout success URL**.

If your application runs at `https://example.com`, users will be redirected to `https://example.com/logged-out.html` after logging out.

> **Important: Allow Access to the Logout Success URL**
>
> Users are no longer authenticated after logging out, so the logout success URL has to be accessible without authentication. Vaadin denies requests to URLs that it doesn’t recognize, so a static page such as `/logged-out.html` needs its own `permitAll()` rule. Without it, users end up on the login view instead. If the logout success URL points to a Flow view, annotate the view with `@AnonymousAllowed` instead.

### <a id="absolute-vs-relative-urls"></a>Absolute vs. Relative URLs

The logout success URL can be either absolute or relative.

- **Absolute URLs** — Start with `https://` or `http://` (e.g., `https://example.com/logged-out`).

- **Relative URLs** — Start with `/` (e.g., `/logged-out.html`).

> **Important: Relative logout URLs must include the context path**
>
> If your application is deployed at `https://example.com/app`, the logout URL should be `/app/logged-out.html`. The request matcher doesn’t include the context path, so it stays `/logged-out.html`.
