Welcome to the Onshape forum! Ask questions and join in the discussions about everything Onshape.
First time visiting? Here are some places to start:- Looking for a certain topic? Check out the categories filter or use Search (upper right).
- Need support? Ask a question to our Community Support category.
- Please submit support tickets for bugs but you can request improvements in the Product Feedback category.
- Be respectful, on topic and if you see a problem, Flag it.
If you would like to contact our Community Manager personally, feel free to send a private message or an email.
Every time I visit the onshape website I need to log in again. Is there a "remember me" option?
Answers
-
Are you clearing private data on closing of Chrome? Your browser should have a cookie with your session that should remove the necessity of signing in again until the cookie expires.Jake RamsleyDirector of Quality Engineering & Release Manager onshape.com1
-
You will need to login again after 4 hours of inactivity. This is an important security feature. We realize that this is more important to some of our users than others. If having this feature is important to you, please open up an Improvement Request in the categories on the right side of the page.John Rousseau / VP, Technical Operations / Onshape Inc.-1
-
Thank you for your answers @john_rousseau and @jakeramsley. However inactivity is not the reason since it happens every time I open the first onshape browser tab irrespective of time elapsed. Regarding cookies, every other website works fine so and I do not delete cookies. I do not even close chrome at all. Every time I open the first onshape chrome tab, my credentials are requested.0
-
Hi @dimitris_mertzis. Sorry you are running into this issue. It's not the way it's supposed to work. It's also not the way it works for everyone else. It looks like you are running Chrome on Windows 10, which is a very common configuration.
Are you running any ad blockers or privacy plugins? Are you signing out of Onshape before you close the tab?
If you can't find a plugin that's causing this, please open a support request from in Onshape via the "?" menu.John Rousseau / VP, Technical Operations / Onshape Inc.0 -
I disagree that frequent automatic logoffs are an important security feature. Does gmail log you off every morning? Please let users make this decision themselves.
2 -
I think the easiest way to bypass this is to set your browser to remember your login info. I do this and it makes logging in much easier2
-
Or use a 3rd-party password manager. I trust Google less and less with any personal info these days and the password manager works fine with Onshape.6
-
This is incredibly annoying, and I disagree with the rationale of it being a security feature. At best, it should be a org/account settingAlso, Onshape stops 1Password from being able to enter passwords which means it's not a solution-3
-
Google Chrome and Safari will both remember and enter passwords for Onshape just fine.Security is a huge concern for most companies adopting SaaS solutions. Onshape has generally adopted best practices for this type of product. Does your bank leave you logged in indefinitely?
The other thing you have to keep in mind is that keeping an active logged in window implies a certain level of back end server load (geometry and modeling), ready to process and communicate with your browser. Those servers cost a lot. If you want to have them active and waiting for you while you go for coffee or sleep, you would need to pay more for that server load somehow.Simon Gatrall | Product Development, Engineering, Design, Onshape | Ex- IDEO, PCH, Unagi, Carbon | LinkedIn
5 -
For myself, no one is going to get much data from me by stealing my models. I would love to always be signed in.
On a separate note regarding comment #5:Gmail != secure; // =P
RENDERCAD
rendercad.ai - Photorealistic product rendering.
▚▞▚▞▚▞▚▞▚
________________________________________________________________________0 -
@andrew_ward338
1Password works well for me with Onshape. Both the browser extension and the desktop version (Windows).
For an enterprise security standpoint - it's important to adopt best practices (per @S1mon) and leverage password managers / 2-step verification whereever possible. If the password manager is setup and working well, it's very low-friction, and best-available security (and fits well with your generally-secured life. You should be using the same strategy for your Gmail and Bank logins too!).
I can see how it's a nuisance for those with a computer that is physically secured, but for folks that travel or work on various machines, this security layer makes Onshape usable.2 -
I, too, am annoyed that OnShape signs me out.
The security argument does not pass muster, esp. because I have a free account and so all my models are public anyway. There are far more people who want to break into a random user's gmail or outlook accounts than OnShape, and those have sane policies which allow me to stay logged in. My password manager, which is far more sensitive, allows me to stay logged in. And then I use that password manager to log into OnShape. If it's safer to aggressively log me out, then it's trivial at best.
If there are CPU reasons, then by all means, log me out. I'm not paying for OnShape, so if I can stretch their dollars that little bit more then I'm happy to periodically click Login.1 -
Onshape will log you out as soon as you close all of your cad.onshape.com browser tabs, which ends your session.
After that your browser should remember your username and password and auto fill them. So you just need to click the login button. That's the way it has always worked for me.
If you don't get the prompt from your browser, that means you probably hit the option to 'never remember for this site' the first time you logged in.
So you will probably have to dig through your browser security settings and saved passwords and add it there.
4 -
I also find the automatic log out as just an annoyance, as opposed to a real security feature. There are so many other secured apps that have no need for this. It's all about reducing friction, so please remove the 4 hour bump (or at least offer people the option to stay logged in on the same PC)
0 -
I think I have a solution for you all, I do this for a work business app and can't see why it would not work for OnshapeDownload, a web page refresh extension for your browser of choice, open a new onshape tab, set the tab to auto refresh every 5 mins or whatever you wish, then pin the tab, so you don't get confused.Now you should be able to use Onshape in a separate tab without it timing out.I hope this helps!!0
-
I imagine that would be incredibly annoying if it refreshed when you're in the middle of sketching.tony_fernandez233 said:I think I have a solution for you all, I do this for a work business app and can't see why it would not work for OnshapeDownload, a web page refresh extension for your browser of choice, open a new onshape tab, set the tab to auto refresh every 5 mins or whatever you wish, then pin the tab, so you don't get confused.Now you should be able to use Onshape in a separate tab without it timing out.I hope this helps!!Senior Director, Technical Services, EMEA1 -
The time out is not bad anymore. You can click the blue bar at the top of the screen and it will allow you to continue working instantly. Refresh is now a last resort1
-
I too am annoyed by the logouts, and the questionable claim that logging people out is a security feature. My PC is locked inside my house, what extra security does logging out add for me?
In fact, I can't think of a scenario where security is actually improved by automatic logout. Let's say someone actually takes my computer, and has logged in to Windows somehow. If they're after my OnShape data, firstly, I have my passwords saved so they can still log right back in without knowing the password. And even if I didn't have passwords saved, they could reset my OnShape password because they've got my computer and thus access to my emails.
Any security conscious person isn't leaving their computer unlocked anyway, so it just seems like a weird decision to make, like no one at OnShape has really thought about security carefully.
Maybe there is some very rare, convoluted scenario you could come up with, a one-in-a-billion occurrence, where automatic logout protects your data, but there's absolutely no reason to make it mandatory for everyone else.
1 -
@davidg707 if you want to have passwords saved to compromise security then that's your choice, but corporations don't want to give their employees that freedom. It's not costing you anything so suck it up.
-2 -
@Paulo saving passwords and keeping OnShape signed in wouldn't "compromise security" on my system, and that's my point. If you build a one-size-fits-all solution for security, then you have to make it as strict as possible, which is what they've done. What I'm suggesting is that this results in bad UX for people who don't need or want that level of security. I'm sure there's a way to both make this an option for individuals, and at an organisation level.
If this isn't a concern for you, then your input on the matter is not required.
-1 -
It's not just physical access auto log out secures. It's also a standard method of preventing cross site attacks.
0 -
always logs me out when I close the tab too aggressive security. onshape should really disable this feature or just add an option to stay logged in/remember me.
1 -
This is a bit of a cop-out, but I just use a password manager. Bitwarden has a shortcut to make it easy.
Ramon Yip | glassboard.com
0 -
On my Mac with Safari, I touch the keyboard once for UserID and once for Password. It takes less than a second. It's only somewhat annoying when I'm juggling work accounts and a personal account on mobile. But even then, it's quick.
Simon Gatrall | Product Development, Engineering, Design, Onshape | Ex- IDEO, PCH, Unagi, Carbon | LinkedIn
0 -
Password managers are the way to go. Either use the built in one in the browser, or get one with a browser extension. Then you just have to click the sign in button. I haven't typed my password in years. I don't even know them.
Or, just don't close your browser. Then it's more like you only log in once or twice a day. If you aren't using it enough to get completely logged out. Then you don't use it enough thoughout the day anyway, so maybe you only need to log in three times some days.. . Not a big deal.
You will never win an argument with a company about reducing thier security… just saying… I don't think they like playing Russian roulette with their life's work.
5 -
Password managers are the way to go.
I use BitWarden and my issue is that at some point, logging in to OnShape is a two step process because at first, only the username field appears so I have to click on Bitwarden and hit fill. Then the Password field appears and I have to click on Bitwarden again and click Fill again. A minor annoyance but if both the username and password fields would appear together like they do on most other websites, then I only have to tell Bitwarden to Fill once. My workaround is to click on bitwarden, copy the password into the paste buffer, then click fill, and then paste the password into the password field.
0 -
Ctrl+Shift+L is the fill shortcut for Bitwarden. If you have 2FA enabled, you can use Ctrl+V for that, after the password. 90% of the time I don't actually click on Bitwarden to log into sites.
Ramon Yip | glassboard.com
0 -
If you bookmark the password page then your username is already pre-filled so you only need to enter the password.
Senior Director, Technical Services, EMEA0 -
The security of cookies is unequivocally the end user's responsibility whether they recognize it or not. For users who do recognize it, not having a "remember me" option is an infuriating inconvenience.
But if OnShape insists that providing a "remember me" option would somehow shift responsibility to themselves, maybe the solution that would please everyone is third-party authentication. If you could log in with Google or whatever, then the security and duration of your authentication becomes the third party's problem.
0










