Task Progress0 of 3 Tasks
0%

Auth Flows

Real login flows: a one-time code from an inbox, a session that expires halfway through a wizard, and a remember-me session that survives a new browser. Test account: tester@qa.test / Passw0rd!. Each task ticks itself when its result box turns green.

1.Two-Step Login

Two-step loginTo do

Demo account: tester@qa.test / Passw0rd!

Inbox

No new mail

Log in with email, password and code
Goal

Log in as tester@qa.test / Passw0rd!. A code arrives in the inbox after a moment; enter it to finish.

2.Session Expires Mid-Task

Session expires mid-taskTo do

Log in first (section 1) to start the wizard.

Finish the wizard
Goal

Start the wizard and finish all three steps. Your session lasts 8 seconds and step 2 takes longer than that, so you will be asked for your password again.

3.Remember Me

Remember meTo do
Load this page with a saved session
Goal

Log in with 'Remember me' ticked. Then open this page in a fresh browser context that starts with the saved storage. You should be logged in without the form.

4. Solutions

Try the challenges yourself first. Reference solutions are hidden until you ask for them.

About this Auth Flows page

Login flow automation is the practice of scripting authentication in browser tests, including multi-step sign-in, session expiry and remembered logins. Tests must handle a second verification step, detect when a session ends partway through a task, and reuse saved cookies or storage instead of logging in each time. This free page lets you practice all three with pass/fail results.

Screenshot of the Auth Flows practice page on QA Playground. Two-step login, sessions that expire mid-task and remembered logins.
Auth Flows: Two-step login, sessions that expire mid-task and remembered logins.

Frequently asked questions

How do you test a session timeout in automation?

Start a task after login, wait for or force the session to expire, then perform the next action and assert the app redirects to login or shows an expired message. Prefer shortening the timeout or clearing the session cookie over using long sleeps.

How does Playwright storageState work for login?

Call context.storageState({ path: 'state.json' }) after logging in, then set use: { storageState: 'state.json' } in the config. New contexts start with those cookies and localStorage applied. It does not capture sessionStorage, and saved state can expire, so refresh it.

How do you automate a two-step login in Selenium?

Fill the first step, click continue, then use an explicit WebDriverWait until the second step's field is visible before typing. Do not assume the second form is in the DOM yet. Assert both the success state and error messages for wrong inputs.

How do you test a remember me checkbox?

Log in with the box checked, close the browser context or reload, open the app again and assert you are still signed in. Repeat unchecked and assert you land on the login page. Check that the persistent cookie has an expiry date.

Is there a free site to practice login automation?

Yes. This page is free, needs no signup and runs in your browser. It has tasks with positive and negative cases, hints, and reference solutions in Playwright, Selenium Java, Selenium Python and Cypress.

Free developer tools on Randomly.online

QA Playground is part of Randomly.online. These tools help while you write and debug tests: