SuperTokens is the most secure solution for user session management - enabling robust prevention and detection of attacks.
We mitigate against all types of attacks (XSS, MITM, session fixation, CSRF etc) and are the only ones that we know of to scalably implement detection of auth token theft (as per the official OAuth 2.0 specifications in RFC 6819). We have solved the scalability, race conditions and failure issues usually associated with this.
Fitbit tried to implement theft detection in 2016 but was unable to do so. Many companies build their own session management solution - which can take weeks to months (depending on developer experience and robustness of their solution). Ours can be rapidly integrated with in a few days.