About Session State and Security

Learn about managing session state and security.

Oracle APEX persists session state in database tables. Session state is preserved in database tables because it is more secure to store the session state on the server side than on the client. Because APEX applications use the stateless HTTP protocol, an application’s session state across multiple page views is preserved in database tables. Not maintaining a synchronous database connection for each APEX application user significantly lessens memory and database resource requirements.

Developers can query the session state stored by APEX applications using the App Builder and built-in monitoring pages. Developers and administrators can access session state for any application in the workspace to which they are authenticated.

Developer best practices for managing session state include:

Tip: You can encrypt item values up to 4000 bytes in length. Attempts to encrypt values longer than 4000 bytes produces an error message.