Nonce
A WordPress nonce is a short token in a form or a link that shows the request came from a page WordPress built for you. Despite the name, it is not used once. It lasts between 12 and 24 hours, and when one fails you see "The link you followed has expired."
- By
- WP Ministry
- Published
In short
- A nonce protects against requests you did not mean to make. It is not a login and gives nobody access.
- By default one lasts between 12 and 24 hours, and it stops working when you log out.
- A failed nonce shows as "The link you followed has expired." Go back, reload the page and try again.
A WordPress nonce is a short token that WordPress puts into the forms and action links of the dashboard and sends with background requests. When the request comes back, WordPress checks the token. A match shows that the request came from a page WordPress built for you, and not from a link on another site that made your browser ask for it.
The word means "number used once", and a WordPress nonce is neither. It is ten letters and numbers, and WordPress's developer documentation says it is not checked for one-time use: the same user gets the same nonce for the same action for hours at a stretch, and it can be sent again and again until it expires. By default it lasts between 12 and 24 hours. It also belongs to one login session, so logging out ends it.
Where you meet it
- In an address. A dashboard link that does something ends in a nonce:
https://example.com/wp-admin/post.php?post=123&action=trash&_wpnonce=b192fc4204. - In a form. A hidden field named
_wpnoncecarries it. - In the block editor. The editor saves through the REST API, and a request to it from a logged-in browser carries the nonce in a header named
X-WP-Nonceor a parameter named_wpnonce. - In a message, when one fails. WordPress answers with status 403 and a plain page that says "The link you followed has expired.", usually with a link that says "Please try again." Older versions said "Are you sure you want to do this?", and WordPress's own glossary still gives that wording. A log-out link without a valid nonce shows "You are attempting to log out of" with the site's name, and asks "Do you really want to log out?" The REST API answers "Cookie check failed", with the code
rest_cookie_invalid_nonce. A background request is usually answered with nothing but-1.
What goes wrong
- The page was open too long. A tab left overnight, or opened before you logged out and in again, holds nonces WordPress no longer accepts. How to fix "Are you sure you want to do this?" starts there, and tells this cause apart from the two that have nothing to do with time.
- A cache kept the page. Visitors who are not logged in all receive the same nonce. A page cache that keeps a form for longer than the nonce lasts hands each of them a dead one. Keep pages with forms out of the cache.
- A 403 that is not a nonce. A failed nonce is a 403 from WordPress with one of the messages above. A 403 that shows a server's or a firewall's page is a refusal from somewhere else: see how to fix the 403 Forbidden error.
- A save fails in the editor. How to fix "Updating failed" shows how to read what came back.
rest_cookie_invalid_nonceis the token. A block page is a firewall. - Everyone's forms fail at once. Nonces are made from two of the site's salts and security keys. When the keys are replaced, every nonce already on a page stops working.
How to look at yours
Open Users, then Profile, in the dashboard. View the page's source and search for _wpnonce. The value beside it is the nonce for saving that form. Reload tomorrow and it will be different.
Common questions
How long does a WordPress nonce last?
Between 12 and 24 hours by default. WordPress counts time in 12-hour halves and accepts a nonce made in the current half or the one before it. A plugin can change the length with the nonce_life filter.
Is a nonce a password?
No. It does not say who you are and it gives no access. WordPress's documentation says never to rely on one for authentication or access control. The nonce only shows that the request started from a page WordPress gave you.

