Session management and security
Infor Mobile Hub maintains a secure session for authenticated users and applies security controls consistently across all modules. Session behavior, timeout limits, authentication methods, and web service validation follow your organization’s configuration.
Access to Infor Mobile Hub can be restricted on devices that do not meet your organization’s security requirements, including rooted or jailbroken devices.
Session lifecycle
Infor Mobile Hub tracks session events such as application launch, resume from background, inactivity timeout, logout, and session expiration.
If the application remains inactive for a configured period, the session locks automatically. The default inactivity timeout is five minutes, although administrators can configure the timeout value based on organizational security requirements.
If a session expires because of inactivity or policy enforcement, Infor Mobile Hub ends the session and requires authentication before access continues.
Session handling applies consistently across all modules.
Re-authentication requirements
Infor Mobile Hub requires re-authentication when the application resumes from the background, after a defined period of inactivity, or after a session ends.
Authentication methods depend on your organization’s policy and can include biometric authentication, a device PIN, an application PIN, a password, or a passkey. These methods can also be used to unlock the application after a session lock.
Authentication rules and timeout policies apply consistently across all modules.
Remote session revocation
An administrator can revoke an active session if a device is lost, compromised, or no longer authorized.
When a session is revoked, Infor Mobile Hub ends the session immediately. You must authenticate again to continue using the application.
Remote session revocation protects organizational data when device security is at risk.
Secure web session handling
Infor Mobile Hub establishes a secure web session for authenticated requests. Before sending a request to backend services, Infor Mobile Hub verifies that the session is valid.
Infor Mobile Hub attaches the required authentication tokens and headers to each request. Backend services process requests only when the session is valid.
If the session is invalid or expired, access is blocked until authentication completes.
Best practices
Log out of Infor Mobile Hub when you finish using the application on shared or unsecured devices.
Enable device security and application-level protection, such as biometrics or an application PIN.
Do not share authentication credentials.
Report lost or compromised devices to your administrator so active sessions can be revoked.
Keep your device operating system updated to maintain compliance with organizational security policies.