Session Management sits at the heart of authentication in single-spa. This guide walks through the concept step by step, with examples, a cheatsheet, and common mistakes to avoid.
Session Management Overview
Session Management is a building block you will reach for often in single-spa. It keeps related logic together and makes your intent obvious to reviewers and future maintainers.
When you learn session management properly, you avoid the guesswork that leads to bugs and rework. The example below shows the shape you will use in most real single-spa projects.
Start from a minimal Session Management example and grow it only as needed.
Keep configuration explicit so Session Management behaves the same in every environment.
Name things clearly so teammates understand your Session Management at a glance.
Add tests around Session Management early to lock in expected behaviour.
Single-SPA Cheatsheet
Core single-spa APIs related to session management.
API
Example
Purpose
registerApplication
registerApplication({ name, app, activeWhen })
Register a micro frontend
activeWhen
activeWhen: ['/checkout']
Route ownership
start
start()
Begin routing
bootstrap
export async function bootstrap()
One-time setup
mount
export async function mount(props)
Render the app
unmount
export async function unmount(props)
Clean up the app
import map
systemjs-importmap
Locate app bundles
How Session Management Works in Single-SPA
Session Management is part of how single-spa lets multiple applications — even in different frameworks — coexist on one page. A root config registers each app and controls when it is active.
single-spa orchestrates multiple framework apps on one page through a root config.
A root config registers apps and calls start().
Each app exports bootstrap, mount, and unmount lifecycles.
activeWhen decides which routes each app owns.
Import maps resolve each app's bundle at runtime.
Practical Guidance for Session Management
For reliable micro frontends, session management should isolate failures and keep shared state minimal. Let each team own its app end to end while agreeing on a few shared contracts.
Concern
Recommendation
Isolation
One app's crash should not break others
Shared state
Prefer shared utility modules over globals
Routing
Keep activeWhen rules explicit and non-overlapping
Deployment
Release via import-map updates per app
Common Mistakes
Skipping error handling and edge cases when wiring up session management.
Leaving session management untested, so regressions slip into production.
Over-engineering session management before you actually need the extra flexibility.
Ignoring documentation, which makes session management hard for the next developer to change.
Key Takeaways
Session Management is a core part of working effectively with single-spa.
Start small and keep session management focused on a single responsibility.
Apply consistent patterns so session management scales across your project.
Test and document session management to keep it maintainable over time.
Pro Tip
Pair session management with automated tests from day one. It is far cheaper to catch single-spa regressions in CI than in production.
You now understand session management in single-spa and how to apply it in real projects. Next, continue with Protected Routes to keep building your skills.