---
title: "HeldSessionState"
description: "the session state of a held identity, sealed with the identities' key and kept in the record, so that every copy of the platform reads one store; the key never enters the record, and no tool returns this row"
section: concepts
address: /concepts/heldsessionstate
contract: 0476e35e6e275db5
---

# HeldSessionState

the session state of a held identity, sealed with the identities' key and kept in the record, so that every copy of the platform reads one store; the key never enters the record, and no tool returns this row

[figure: HeldSessionState is a definition at tenant scope. The drawing shows its fields and the objects that they point at.]

| property | value |
|---|---|
| kind | definition |
| scope | tenant |
| key | the identity's store entry |
| store | postgres |
| family | sources |



## Fields


| field | type | required | note |
|---|---|---|---|
| `vault_entry` | `id` | yes | the identity's store entry, which its SignedInIdentity row carries |
| `key_name` | `text` | yes | the environment name of the key that sealed the state |
| `nonce` | `text` | no | the seal's nonce as hex; absent when the state was forgotten |
| `sealed` | `text` | no | the sealed session state as hex; absent when the state was forgotten |
| `checkpointed_at` | `time` | yes |  |



## Routes that use it
No route takes or returns HeldSessionState directly. The record holds it, and the objects that point at it reach it.
