Sessions

The General → Sessions page controls how long users remain signed in to your website.

HMDIA lets you set different session durations for Administrators and Other users, and optionally display a countdown warning shortly before a session expires.

Sign-in session timeout is a Pro feature.

Sessions


Sign-in Session Timeout

Use Sign-in session timeout to set the lifetime of the authentication session created when a user signs in.

Administrators and other users can have different timeout periods.

Administrators

Set how long users with the Administrator role should remain signed in.

Enter a number and choose a unit:

  • Minutes
  • Hours
  • Days

 

For example:

90 Days means an administrator’s HMDIA-managed sign-in session can remain valid for up to 90 days.

Use 0 for the WordPress Default

Enter 0 if you do not want HMDIA to set a custom session duration for administrators.

When set to 0, the plugin keeps the normal WordPress authentication expiration instead.

Other users

Set the session duration for users who are not Administrators.

This includes roles such as:

  • Subscriber
  • Customer
  • Contributor
  • Author
  • Editor
  • Other custom WordPress roles

 

As with Administrators, enter a number and select:

  • Minutes
  • Hours
  • Days

 

For example, the setting shown in the screenshot:

30 Minutes

means non-administrator sessions expire after 30 minutes.

Set the value to 0 to keep WordPress’s normal session expiration instead.

Why Use Separate Session Durations?

Separating administrator and user sessions lets you apply different security policies to different account types.

For example, you may want:

  • Administrators to remain signed in longer on a trusted management device.
  • Customer or member sessions to expire sooner.
  • Both groups to use different timeout policies based on how your website is used.

 

Choose durations appropriate for your website’s security requirements.

Session Expiry Warning

Enable Session expiry warning to notify a signed-in user shortly before their HMDIA session expires.

When enabled, HMDIA displays a countdown popup before automatic logout.

This gives the user an opportunity to continue the current session instead of unexpectedly being signed out.

Show Warning Before Logout

Choose how early the session-expiry warning should appear.

Available options are:

SettingWarning appears
30 seconds30 seconds before logout
1 minute1 minute before logout
2 minutes2 minutes before logout
5 minutes5 minutes before logout

In your screenshot, this is configured to 30 seconds.

Short Sessions

If the configured session duration is shorter than the selected warning period, HMDIA automatically uses a shorter warning period.

This prevents the expiry popup from appearing immediately after the user signs in.

Staying Signed In

When the expiry warning appears, the user can choose to stay signed in.

Choosing this option refreshes the current authenticated session, allowing the user to continue without signing in again.

It does not create or refresh other sessions the same user may have open on other browsers or devices.

When the Countdown Reaches Zero

If the user does not extend the session before the countdown reaches zero:

  1. HMDIA signs the user out.
  2. The current authenticated session ends.
  3. The user is redirected to the configured HMDIA Login page.

 

HMDIA does not preserve the page the user was viewing as a return URL when the session expires.

After signing in again, the normal HMDIA sign-in redirect settings apply.

Sessions vs. Remember Me

The Sessions settings control the HMDIA session lifetime.

The Remember me option on the Login form is a separate login option.

When you configure a custom HMDIA session timeout, that timeout provides the session policy for the applicable user group. If the HMDIA duration is set to 0, WordPress handles the normal authentication expiration.

Example Configuration

A configuration such as the one shown in your screenshot would work as follows:

Administrators: 90 Days
Administrators remain signed in for up to 90 days.

Other users: 30 Minutes
Non-administrator users are signed out after a 30-minute session.

Session expiry warning: Enabled

Show warning before logout: 30 seconds
A countdown appears shortly before the session expires, allowing the user to stay signed in.

This is only an example—you can configure each duration according to your site’s requirements.