Old Sessions and Forgotten App Grants on X: A Complete Audit
The way accounts actually get taken over is duller than most people imagine. It is not credential stuffing, and it is not SIM cloning. It is an app you approved once three years ago, or a session still attached to a device you sold or reinstalled long ago. Both survive a password change.
Here is a full session audit: what is authorising what, which grants to revoke, and where the audit belongs relative to a deletion run.
Two different kinds of login residue
| Kind | Where to look | What revoking does |
|---|---|---|
| Connected third-party apps | App permission list in settings | Schedulers, analytics and check-in tools that rely on the grant stop working immediately |
| Active sessions and login history | Device and session list in security settings | That device must sign in again; others are unaffected |
People lump these together, but they answer different questions. A grant is what someone else can do on your behalf. A session is who is still sitting inside your account.
Step one: clear the connected apps
That list is usually longer than expected. Years of scheduling tools, stats dashboards, giveaway scripts and services you no longer recognise accumulate in it. For each entry, check three things: do you still need it, does its scope include posting or reading direct messages, and does the company still exist.
The last one gets missed. When a service shuts down, you may not even be able to open its site anymore, yet the grant stays attached to your account. Revoke those first. There is never a reason to keep one.
Step two: read the device and session list
Do not sign everything out the moment you see an unfamiliar entry. Most of them are old phones, tablets or browsers showing up under an unhelpful device name. Compare login times and locations against your own schedule instead.
- It lines up: fine, but an old device can still be signed out as a housekeeping step.
- It does not line up and the location is unfamiliar: change the password, revoke that session, then check your inbox for unexpected sign-in notices.
- Location is plausible but the time is wrong: usually a proxy or VPN exit address. Confirm the device itself is yours and move on.
Step three: add a second factor
The audit cleans up history. Two-factor authentication handles the next attempt. One does not replace the other. With a second factor enabled, a leaked password alone no longer produces a session. Prefer app-generated codes over SMS, since the SMS channel carries SIM-swap risk.
Sequence matters: audit before you delete
This is the part people get backwards. A deletion run needs the account to stay signed in and will call the API repeatedly over a long stretch. If an unknown session is still alive, you are cleaning content while exposing a new set of operations through an entry point you do not control. The order is: revoke grants, clear sessions, enable the second factor, then start deleting.
Also avoid swapping your main device or signing out everywhere mid-run. Losing the login halfway through makes resuming from a breakpoint far messier than it needs to be.
Recheck a week later
Revoking a grant or ending a session produces no notification, so silence is not confirmation. Open both lists again a week later. If a service has reappeared, something you still use is re-authorising it on your behalf, and that is worth knowing before you assume the account is buttoned up.
About digital-footprint-health.shop
digital-footprint-health.shop keeps checking and cleaning as separate steps. Run a footprint check on your X archive locally first and you get a 0-100 health score plus a risk list; once the account side is settled, start deleting. The archive is never uploaded and the check is free. Begin with the free check, follow the two-factor setup guide for the account side, and use the deletion walkthrough when you are ready.
Frequently Asked Questions
What is the difference between an app grant and a session?
A grant answers what someone else can do on your behalf, like posting or reading messages. A session answers who is still signed in. Revoking a grant breaks the tool immediately; signing out a session affects only that device.
I see an unfamiliar device. Should I sign everything out?
Not immediately. Most are old phones or browsers with unhelpful names. Compare timestamps and locations against your own schedule. Matching ones can be signed out as housekeeping; a mismatch with an unfamiliar location calls for a password change and revocation.
Why does the audit go before deletion?
A deletion run keeps the account signed in and calls the API repeatedly over a long stretch. If an unknown session is still alive, you clean content while exposing new operations through an entry point you do not control. Revoke, clear sessions, enable the second factor, then delete.
Check your own X/Twitter footprint
Free on-device scan. Your archive never leaves your computer.
Start Free Check