Skip to content
Performance & Accessibility

Session Timeouts and Time Limits, Done Properly

Time limits on tasks, such as sessions that expire, forms that time out and offers that reset, and how people are warned and given more time.

Marcus Adeyemi Technical Director 2 min read 20 views
Session Timeouts and Time Limits, Done Properly

What is at stake

People who read, type or move more slowly lose work when sessions expire without warning, and WCAG requires time limits to be adjustable at level A.

The playbook

  1. Warn users before a session expires
  2. Let users extend with a single action
  3. Save form progress so it survives a timeout
  4. Tell users about time limits before they start
  5. Make warnings accessible to screen readers

Where it goes wrong

Avoid:

  • Silent session expiry that discards form data
  • Countdown warnings that are not announced
  • Short limits on multi-step forms
  • Requiring users to start over after a timeout
What to do and what to avoid with session timeouts and time limits, side by side
Good practice against the usual mistakes, from the sources listed below.

The numbers behind it

Published figures for Session Timeouts and Time Limits
MeasureFigure
WCAG 2.2.1 Timing Adjustable, Ausers can turn off, adjust or extend time limits, with at least 20 seconds to extend
Extensionusers must be able to extend at least ten times with a simple action
Exceptionsreal-time events and limits longer than 20 hours
WCAG 2.2.6 Timeouts, AAAusers are warned about inactivity timeouts that could cause data loss

Getting outside help

When to hand it over: Bring in help when banking, government or checkout flows use strict timeouts, or when users report losing work.

Where this comes from

The figures and practices above come from the sources listed.

Working on something like this?

We take on Performance & Accessibility work for teams who want it done once, properly. Tell us what you are building and we will tell you honestly whether we are the right studio for it. Start a project.

Where to go next

Spotted something wrong? Report an error on this page. We correct on the page and say what changed.

All services

The work behind this article, and what it costs.

Marcus Adeyemi

Builds and maintains the web work. Writes about front-end architecture, performance, accessibility and the unglamorous parts of keeping a site alive.

Keep reading

More in Performance & Accessibility