This is the table you'll look at most. It answers "what's actually authenticated against my app right now, from where, since when, and for how much longer?"
What to show per row
| Column | Why | Display tip |
|---|---|---|
| Token prefix (8 chars) | Lets you correlate with audit log without exposing full token | Use monospace |
| IP | Tells you which device this is | Annotate known IPs ("My Laptop", "Phone (Tailscale)") |
| Created at | How long ago the login happened | Relative ("3 hours ago") + tooltip with absolute |
| Expires at / time left | When it'll auto-die | Color: red if <30min, gray otherwise |
| "Revoke" button | Surgical kill | Inline, requires confirm |
Sorting and filtering
Don't add a sort/filter framework. Solo apps rarely have more than 5 active sessions. Sort by created_at desc and stop. If you ever have 50, you have a different problem worth investigating manually.