Session Idle Timeout and Auth Token Lifetime are advance features that can be configured in either a COS or for individual accounts.
When a user logs on to the Zimbra Web Client and checks "remember me" on the log on page, the Auth Token Lifetime feature sets a browser cookie that contains the auth token. The user can open the Zimbra Web Client without having to log on again until the auth token expires. A lifetime can be measured in days, hours, minutes, or seconds. The default is 2 days.
The Session Idle Timeout determines how long a user session remains active if there is no activity on the Zimbra Web Client. Activity includes any clickable mouse action such as viewing the contents of a folder or clicking a command button. When there is no activity within the configured time, the user is logged out of the Zimbra Web Client.
Setting limits for both of these features limits the exposure of a user's information on shared computers. When a session times out, the auth token automatically expires.