MentorNode
Start free
Caching & Content DeliveryMediumdesign-session-store

Design a Global Session & Token Store

Design where login state lives for a multi-region app: fast enough to check on every request, revocable within seconds, and surviving a region loss.

Sticky vs Stateless SessionsToken RevocationReplicated CacheTTL Sweeping
Traffic & Capacity Estimates:

80M active sessions · 400k session lookups/second · 3 regions

Functional Requirements

  • •Create, look up, refresh, and revoke a session from any region.
  • •Support instant global logout of one device, all devices, or all sessions for a compromised account.
  • •Expire idle sessions automatically and enforce an absolute maximum lifetime.
  • •Record device and IP metadata so a user can review their active sessions.

Non-Functional Requirements

  • •Session validation under 2ms, without a cross-region hop.
  • •A revocation must take effect globally within 10 seconds.
  • •Losing a region must not log out that region's users once traffic fails over.

Back-of-the-Envelope Math

  • 80M sessions * 500 bytes = 40 GB — small enough to replicate fully to every region.
  • 400k lookups/s is the whole request volume; this store is on every authenticated path.

Key Architectural Trade-offs

  • Stateless JWTs (no lookup, revocation needs a deny-list anyway) vs server-side sessions (revocable by construction, a lookup on every request).
  • Short access tokens plus refresh tokens shrink the revocation window without paying for a lookup on every call.
  • Asynchronous cross-region replication is fast but lets a just-revoked token work briefly in another region — a quorum write fixes it and costs latency.

Click or drag a component onto the canvas, then connect the handles to draw the data flow.

3 nodes · 2 edges

Components · 35

Client & Edge4
Compute & Gateway7
Storage & Caching11
Messaging & Streaming6
Coordination & Ops5
Intelligence2
Canvas overview