Login - Don't Log Me Out/Extend Log Out Time (more than 60 minutes)
Develop the feature where Xero doesn't log user out time is extended for more than 60 minutes when it’s idle.
Purpose: Because having to log in again can disrupt users' workflow, which some users had to be interrupted as they’re also taking care of their business at the same time.
Hi everyone, we appreciate the interest surrounding this idea, however we want to be open that we're unable to extend our log-out time past 60 minutes. Xero hold a lot of sensitive information including bank data and we're required to be as secure as online banking.
Any session information running on a web browser can potentially be stolen. If the session does not time out. You then have an infinitely long vulnerability window to session hijacking. Our best option is to keep a tight expiration window on the session cookie, and regenerate them frequently. Even setting a long timeout doesn't help with this - too long a timeout will greatly increase the risk of invasion or potentially jeopardise your personal data and the safety and integrity of the Xero application itself. This is why we maintain control of this.
If we detect there's been no activity on a page (e.g move movements, clicks, keyboard) for 10 minutes you'll receive an inactivity prompt ('Hey Kelly, are you still there?') and if your session reaches 60 minutes you'll be redirected to the login page.
- As a suggestion you can periodically refresh the screen <F5> to prevent the security timeout kicking in.
In more recent comments here it sounds like some of you are having issues with the login process or staying logged into Xero for less than 60 minutes. If you're experiencing unexpected behaviour, we'd highly recommend raising a case with our team of specialists at Xero Support where we have tools to investigate and confirm what's going on - Any details you can provide the team on the page you're trying to sign in from (e.g URL, error 500 received) or actions you were making when the login issue occurred will help. Thanks
-
Carly Blackney commented
I agree. This is becoming extremely frustrating. The 30-day option would be ideal but I would settle for the 14-day log-in to be reinstated.
-
Jared Fitzclarence commented
Previously you were able to stay logged in for up to 14 days. This was ok (30 days would have been even better), but recent it was changed so you have to log in every day. This is incredibly annoying and is encouraging users to disable 2FA, which in turn reduces security.
Can you please change it back so that I can stay logged in for longer on my device.
Ideally this would end up as a setting in Xero where either the user could set their own log in duration from some options, or the administrator of the account could determine the maximum stay logged in duration for the Xero Organisation
-
Christopher Moore commented
My particular problem with this is for Time Logging in Projects. Xero has usually logged out when we want to add a time record, which means they don't get logged as diligently as they should and money gets lost!
I get that there may be regs for auto-timeout on the critical ledger access, and that security is critical, but to enforce the same rules on someone entering a time entry - which needs authorising anyway - means that logging doesn't happen reliably.
How can a vendor that's so deaf and unresponsive still be in business? 1 full year in for us and I'm close to looking for an alternative. So much that's really neat but so many issues that bomb productivity and usefulness to the point of unusability.
-
Hernan Puente commented
Is it worth commenting considering this is a 10-year unattended request? Paying $70/month and having to log in 10 times a day seems unfair.
-
Tim Vosper commented
I've submitted a case today, directly referring to this issue (unaware this was an idea shared 10+ years ago and still not addressed!!!)
The number of login's per day is frustrating, noting this isn't a problem with other accounting software I've used.
The 10 years + of waiting on any action here would indicate it will never likely be resolved or concerns addressed here. I was just handballed a link to this 10 year old idea...not ideal.
-
Luke Armstrong commented
I don't think Xero are going to fix this. As part of ATO regulations (in Australia) digital service providers linked to ATO are required to have MFA or two factor authentication (I'm assuming specifically for income tax/BAS security).
Not sure why this also affects the 60 minute time out but seems related due to previous information from Xero community.They could split tax payments and reporting into a separate part of Xero that needs it's own extra authentication.
In the meanwhile, if you are using your own desktop PC that only you can access, a possible workaround is to use your internet browser's password manager to remember your details*.
You will still need to authenticate every 24 hours. You will still need to log in again after whatever arbitrary time period Xero deems as inactivity, but it's only a few clicks instead of re-typing everything again and again and again and again.
It is unfortunate that we need to come up with workarounds for this obviously common problem and that Xero can offer no alternatives.
*You know how secure your PC is or is not. Caveat Emptor Let the buyer beware.
-
Justin Brown commented
It painful having to login 10 times a day. Better things to do when running a bunsiness. how do we extend login for 10 hours?
-
Daniel Kinnoch commented
Wow cannot believe this is a 10-year-old issue. I agree with all the comments below.
-
Robert de Rooy commented
I have solved this problem with a simple workaround if you are a Google chrome user.
Firstly add the chrome extension 'Easy Auto Refresh', then pin it to your taskbar. (see Screenshot attachment of the extension)
Next navigate to your Xero Tab in chrome and click on the extension icon, set it to 600 seconds and your Xero will refresh every 10 minutes.
It displays a countdown in the last ten seconds near the extension icon on the free version of the extension. You can pay for the advanced extension which will show the total seconds left before refresh.
It is very easy to turn off whilst working in Xero, or if you see the 10 second timer just turn the refresh off so it does not refresh while you are working on something.
-
Wendy Jones commented
Seems Xero has absolutely no intention of listening to their customers and even attempting to make this issue less disruptive.
I like many others find it extremely frustrating whilst working between 3 different systems to be continually logging in to Xero throughout the course of my work day. I have now disabled 2 factor authentication in an attempt to minimise the multiple login downtimes. Disabling a security feature is definitely not a good work around!
Given the time we lose in a day perhaps you could find a similar amount of time to respond? -
Jan Sovak commented
Relly Xero, how this could be beautiful accounting when I lose 3 minutes every day a few times waiting to get signed in. Please provide us with Google Auth. or something similar, or let us whitelist some IP addresses from where this will not be necessary to do every 60 minutes or so. And give us some feedback on this as there were no responses from the Xero team on this for quite some time.
-
Clare Dingle commented
Adjusting the time-out would be absolutely wonderful - it is so disruptive to be logging in so frequently.
Looking at this request, it seems users have been asking for this for almost 10 years. Why is Xero so slow to respond?
-
Simon Leaity commented
Seriously Xero this is nearly 10yrs old, it is fustrating and slow
-
Vicki Brookes commented
Yes please. At lease give options to this extremely annoying feature. So annoying all day to be doing this. Come on please asap
-
Elizabeth Nuss commented
It's not unusual to allow the account holder/administrator to personalise the time before the software logs company users out.
Surely we can all be responsible for managing the risk in Xero according to our company needs.
-
David Baker commented
As with not being able to post a payment under bills to pay unless in home currency this issue also seems ot have been around for such a long time. So many people work from home on their own, and it really does not make sense to not enable them to etend this time. Xero is losing rapidly its reputation as responsive to its users needs when compared to other cloud based accounting packages not only amongst users but also accountants who promote to their clients.
-
Jo Murray commented
I use the Xero projects and tasks feature along with the Xero timer to log my time while working. I use this timer/tasks all day every day. It's so tedious with the system constantly logging me throughout the day. What's the point of a project timer if I can't use it effectively?
-
Rachael Hardacre commented
Please fix this.
-
Gretel O'Malley commented
Working on something and go to lunch, come back and have to reset a dozen reports from scratch... so often
-
Tony White commented
OMG!!!! CAN I VOTE FOR THIS TO CHANGE 40 OR MORE TIMES............ soooooo over having to log in again and again and again and again and again and again and again (get the message😡) Please fix this..........