Well, reason seems to dictate that if a person enters a password correctly the first time, then you would have no need to verify the password on subsequent requests during the active session. But, choices of data passage are n umerous (via web) $QUERY_STRING, post vars, etc... read up a bit...