Operable · Level AAA · Introduced in WCAG 2.0

WCAG 2.2.5: Re-authenticating

Published by whatisADA / Grow Wild Agency · Updated

What this criterion means

At Level AAA, a user whose authenticated session expires can sign in again and continue without losing data. Preserve the task state through the authentication transition in a way suitable for the information involved.

A practical example

Someone drafts a grant application and returns after the session expires. After signing in again, the saved draft, selected options and current step are restored so the application can continue.

How to check it

  1. Enter representative information into a multi-step authenticated task.
  2. Allow the session to expire and complete the normal re-authentication process.
  3. Check the restored values, selected files where feasible, workflow position and pending actions for lost work or unintended submission.

What can be missed

A successful login redirect is not proof of state recovery. Sensitive drafts need an appropriate storage and retention design; do not solve data loss by exposing private information on a shared device.

Record your test

Use this worksheet to record what you actually checked. Notes stay on this device when you choose Save; they are not sent to us. Avoid personal or confidential information on shared devices.

These are your observations, not automated results or a conformance certificate. A complete evaluation needs appropriate scope, supported technologies, all applicable criteria and relevant page states.

Primary sources and scope

This is independent implementation guidance with original examples. The linked standard contains the full definitions, exceptions and conformance requirements. A criterion or checklist alone does not establish legal applicability or whole-site conformance.