Keep getting logged out


Website Feedback


I keep getting logged out from this website, including after what seems to be an unreasonably short amount of time. This has been the case for quite a while (possibly for years, I don't know).

I have been unable to find any setting that is meant to control how long logins should be considered valid for.

The site's "sessionid" cookie that is currently on my computer says that it is valid until about a year from now, but I am confident that I will be logged out soon nonetheless (not through my own action).

After having been logged out, the site does (at least sometimes) still remember what account I had last used to log in (e.g. there's a "click here if you are not rwv37" link, or something like that), but it doesn't let me do anything unless I log in again.

Is there anything that can be done to prevent this? Or any other information that I may be able to provide which might help with troubleshooting it?

If possible, I would greatly prefer to be kept logged in essentially indefinitely, until I explicitly choose to log out (or use a different computer or whatever).


Months with no response... anyway, I've discovered some more information that may be of interest if there's anyone out there in Paizo support:

I've discovered that if I just keep a browser tab open on the "Digital Content" page, I can use that page indefinitely (at least for several days, I haven't tried past that). But if I close that page, and try to get back to it using the "Digital Content" menu item from the "My Account" download, it acts as if I have logged out (no matter how long or short of a time I had been logged in).

This is also the case with some -- but NOT all -- of the other menu items from "My Account". All in all:

"Order History": Acts as if I have logged out
"Digital Content": Acts as if I have logged out
"Private Messages": Does NOT act as if I have logged out
"Organized Play": Acts as if I have logged out
"My Profile": Does NOT act as if I have logged out
"Account Settings": Acts as if I have logged out
"Sign Out": I assume this would log me out, but I haven't tried.

I've also discovered that it doesn't REALLY log me out even if I go to one of the ones that "acts as if I have logged out". For example, right now, I am typing this forum post in a browser tab that I have previously tried to go to "Digital Content" with (at which point it told me I needed to log in). But then I clicked on "My Profile", navigated to this old post of mine, and here I am typing a reply while logged in -- WITHOUT having logged in again when it told me I had to do so on the "Digital Content" page.

I really don't care about anything except the "Digital Content" tab. I would like to be able to download my content without having to worry about remembering to keep the tab open. It will take me months to download it all (thanks to the lack of batch or otherwise automated downloading), so anything that slows the process down -- such as forcing me to log in over and over and over -- is, well, not good.

Could someone please look into this? Thanks.

Silver Crusade

Pretty sure there are specific timeouts for My Account items for increased security on that part. You have to prove you are who you are to, for instance, change your password or order or cancel a product or get access to identifiable information. It's fairly common or was fairly common, for certain things in various web platforms to allow you to use a lot of different functions and then have to prove you are who you are for things that need to be more secure. Also, pretty sure the site has been like that for a decade at least on purpose because of standards for credit cards and such. Personally identifiable information should be extremely secure on any site that takes credit cards.

Though if it logs you out, ie, going back to just the normal forums requires you to login, that might be a bug but it could also be increased security, ie, the authentication cookie is removed and reauthentication is required at that point, which would be an easy way of accomplishing that and adding security that says, if you can't login here, you shouldn't have access to anything else at this point either which I could see being reasonable.


I doubt that it's "specific timeouts". As I said, I can keep the page open for days on end, and it will continue to work perfectly well, but as soon as I navigate away from the page -- even if immediately -- it no longer works until I log in again.

Moreover, I can get to, for example, my private messages. I can change my profile info. I can (as I'm doing right now) post to the forums as myself. And other things. If it's for "increased security", it's either poorly thought out or else buggy.

In any case, the current behavior is not reasonable.

Community / Forums / Paizo / Website Feedback / Keep getting logged out All Messageboards

Want to post a reply? Sign in.
Recent threads in Website Feedback