Ffile2fix
Sign in Get started

How to fix the WordPress wp-admin login redirect loop

wp-admin login redirect loop (wp-login.php?redirect_to=...&reauth=1)

You log in successfully, but WordPress cannot read the authentication cookie on the next request and sends you back to the login form with reauth=1. The cookie is being set for a different domain, path or scheme than the one wp-admin is loaded on, or is being stripped.

Also appears as: WordPress login page keeps refreshing after entering the correct password · Redirected back to wp-login.php?reauth=1 after login · Can't log in to wp-admin, login page just reloads

Common causes

  • siteurl and home differ in www vs non-www or http vs https
  • Site moved to HTTPS behind a proxy, CDN or load balancer without telling WordPress the request is secure
  • A page cache or CDN caching wp-login.php or wp-admin responses
  • Stale or conflicting cookies from an old domain
  • A security or redirect plugin forcing a URL that conflicts with WordPress settings
  • COOKIE_DOMAIN or ADMIN_COOKIE_PATH set incorrectly in wp-config.php

How to fix it

  1. Clear cookies for the site. Delete all cookies for the domain (including www and non-www variants) or test in a private window. Stale wordpress_logged_in_ cookies are a frequent trigger.
  2. Make siteurl and home match the real URL. Check both values with wp option get siteurl and wp option get home, or in wp_options via phpMyAdmin. Both must use the exact scheme and host you browse to.
  3. Force the URLs in wp-config.php. Temporarily define WP_HOME and WP_SITEURL with the correct https URL to override the database values while you fix things.
  4. Tell WordPress about HTTPS behind a proxy. If Cloudflare, a load balancer or Nginx proxy terminates SSL, WordPress sees plain HTTP and loops. Set $_SERVER['HTTPS'] = 'on' when the X-Forwarded-Proto header is https, but only if your proxy sets that header.
  5. Exclude login and admin from caching. In your caching plugin, host cache and CDN, bypass /wp-login.php, /wp-admin/ and requests with wordpress_logged_in cookies.
  6. Disable plugins to rule out conflicts. Rename wp-content/plugins temporarily. If you can log in, re-enable plugins one by one, starting with security, SSL and redirect plugins.

wp-config.php (above 'That's all, stop editing!')

define( 'WP_HOME', 'https://example.com' );
define( 'WP_SITEURL', 'https://example.com' );

// Only behind a trusted proxy that sets this header
if ( isset( $_SERVER['HTTP_X_FORWARDED_PROTO'] )
    && $_SERVER['HTTP_X_FORWARDED_PROTO'] === 'https' ) {
    $_SERVER['HTTPS'] = 'on';
}

How to stop it happening again

  • Pick one canonical host (www or not) and redirect the other at the server level
  • Never cache wp-admin or wp-login.php at any layer
  • Update siteurl and home together when switching to HTTPS

Frequently asked questions

Why does the URL contain reauth=1?

WordPress adds reauth=1 when it redirected you to log in because no valid auth cookie was found on an admin request. It means the login succeeded but the cookie was not seen afterwards.

Can I reset my password instead?

A password reset does not help if the password is correct; the problem is cookies or URLs. Fix the URL mismatch or caching first.

It started after enabling Cloudflare. Why?

With Flexible SSL, Cloudflare talks to your server over HTTP while WordPress is configured for HTTPS, causing loops. Install a certificate on the origin and use Full (strict) mode.