[GH-ISSUE #7123] Unable to log in with SSO only #30112

Closed
opened 2026-06-17 09:50:40 -05:00 by GiteaMirror · 7 comments
Owner

Originally created by @uka001 on GitHub (Apr 22, 2026).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7123

Prerequisites

Vaultwarden Support String

Your environment (Generated via diagnostics page)

  • Vaultwarden version: v1.35.7
  • Web-vault version: v2026.2.0
  • OS/Arch: linux/x86_64
  • Running within a container: false (Base: Not applicable)
  • Database type: PostgreSQL
  • Database version: PostgreSQL 17.0 (Debian 17.0-1.pgdg110+1) on x86_64-pc-linux-gnu, compiled by gcc (Debian 10.2.1-6) 10.2.1 20210110, 64-bit
  • Uses config.json: false
  • Uses a reverse proxy: true
  • IP Header check: true (X-Real-IP)
  • Internet access: true
  • Internet access via a proxy: false
  • DNS Check: true
  • Browser/Server Time Check: true
  • Server/NTP Time Check: true
  • Domain Configuration Check: true
  • HTTPS Check: true
  • Websocket Check: true
  • HTTP Response Checks: true

Config & Details (Generated via diagnostics page)

Show Config & Details

Config:

{
  "_duo_akey": null,
  "_enable_duo": true,
  "_enable_email_2fa": true,
  "_enable_smtp": true,
  "_enable_yubico": true,
  "_icon_service_csp": "",
  "_icon_service_url": "",
  "_ip_header_enabled": true,
  "_max_note_size": 10000,
  "_smtp_img_src": "***:",
  "admin_ratelimit_max_burst": 3,
  "admin_ratelimit_seconds": 300,
  "admin_session_lifetime": 20,
  "admin_token": "***",
  "allowed_connect_src": "",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "data/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": false,
  "data_folder": "data",
  "database_conn_init": "",
  "database_idle_timeout": 600,
  "database_max_conns": 10,
  "database_min_conns": 2,
  "database_timeout": 30,
  "database_url": "**********://**************************************************************************************************************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "dns_prefer_ipv6": false,
  "domain": "*****://**********************",
  "domain_origin": "*****://**********************",
  "domain_path": "",
  "domain_set": true,
  "duo_context_purge_schedule": "30 * * * * *",
  "duo_host": null,
  "duo_ikey": null,
  "duo_skey": null,
  "duo_use_iframe": false,
  "email_2fa_auto_fallback": false,
  "email_2fa_enforce_on_verified_invite": false,
  "email_attempts_limit": 3,
  "email_change_allowed": true,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": true,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "enable_websocket": true,
  "enforce_single_org_with_reset_pw_policy": false,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "http_request_block_non_global_ips": true,
  "http_request_block_regex": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "data/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "internal",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 3,
  "increase_note_size_limit": false,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "Vaultwarden",
  "invitations_allowed": true,
  "ip_header": "X-Real-IP",
  "job_poll_interval_ms": 30000,
  "log_file": null,
  "log_level": "info",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  "login_ratelimit_max_burst": 10,
  "login_ratelimit_seconds": 60,
  "org_attachment_limit": null,
  "org_creation_users": "",
  "org_events_enabled": false,
  "org_groups_enabled": false,
  "password_hints_allowed": true,
  "password_iterations": 600000,
  "purge_incomplete_sso_auth": "0 20 0 * * *",
  "push_enabled": false,
  "push_identity_uri": "https://identity.bitwarden.com",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://push.bitwarden.com",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "data/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "data/sends",
  "show_password_hint": false,
  "signups_allowed": true,
  "signups_domains_whitelist": "",
  "signups_verify": true,
  "signups_verify_resend_limit": 6,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": null,
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": null,
  "smtp_from": "******************",
  "smtp_from_name": "***************",
  "smtp_host": "***********",
  "smtp_password": "***",
  "smtp_port": 587,
  "smtp_security": "starttls",
  "smtp_ssl": null,
  "smtp_timeout": 15,
  "smtp_username": "***********",
  "sso_allow_unknown_email_verification": true,
  "sso_audience_trusted": null,
  "sso_auth_only_not_session": false,
  "sso_authority": "*****://*******************************************************************",
  "sso_authorize_extra_params": "",
  "sso_callback_path": "*****://***************************************************",
  "sso_client_cache_expiration": 0,
  "sso_client_id": "************************************",
  "sso_client_secret": "***",
  "sso_debug_tokens": false,
  "sso_enabled": true,
  "sso_master_password_policy": null,
  "sso_only": true,
  "sso_pkce": true,
  "sso_scopes": "email profile",
  "sso_signups_match_email": true,
  "templates_folder": "data/templates",
  "tmp_folder": "data/tmp",
  "trash_auto_delete_days": null,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "yubico_client_id": null,
  "yubico_secret_key": null,
  "yubico_server": null
}

Vaultwarden Build Version

V1.35.7

Deployment method

Official Container Image

Custom deployment method

It is deployed in kubernetes. Using gitlab as SOT and ArgoCD.

Reverse Proxy

no

Host/Server Operating System

Linux

Operating System Version

No response

Clients

CLI, Web Vault

Client Version

Firefox v2026.2.0

Steps To Reproduce

  1. Go to the login page.
  2. Fill in an email address (SSO/Microsoft entraID from the organization)
  3. Login
  4. MFA
  5. Returns back to login screen without any errors
  6. Try again
  7. Cry

Expected Result

Successful login using SSO.

Actual Result

A loop whereby the user is redirected to the login screen after finishing the MFA (microsoft authenticator)

Logs


Screenshots or Videos

No response

Additional Context

No response

Originally created by @uka001 on GitHub (Apr 22, 2026). Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7123 ### Prerequisites - [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=) - [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/) ### Vaultwarden Support String ### Your environment (Generated via diagnostics page) * Vaultwarden version: v1.35.7 * Web-vault version: v2026.2.0 * OS/Arch: linux/x86_64 * Running within a container: false (Base: Not applicable) * Database type: PostgreSQL * Database version: PostgreSQL 17.0 (Debian 17.0-1.pgdg110+1) on x86_64-pc-linux-gnu, compiled by gcc (Debian 10.2.1-6) 10.2.1 20210110, 64-bit * Uses config.json: false * Uses a reverse proxy: true * IP Header check: true (X-Real-IP) * Internet access: true * Internet access via a proxy: false * DNS Check: true * Browser/Server Time Check: true * Server/NTP Time Check: true * Domain Configuration Check: true * HTTPS Check: true * Websocket Check: true * HTTP Response Checks: true ### Config & Details (Generated via diagnostics page) <details><summary>Show Config & Details</summary> **Config:** ```json { "_duo_akey": null, "_enable_duo": true, "_enable_email_2fa": true, "_enable_smtp": true, "_enable_yubico": true, "_icon_service_csp": "", "_icon_service_url": "", "_ip_header_enabled": true, "_max_note_size": 10000, "_smtp_img_src": "***:", "admin_ratelimit_max_burst": 3, "admin_ratelimit_seconds": 300, "admin_session_lifetime": 20, "admin_token": "***", "allowed_connect_src": "", "allowed_iframe_ancestors": "", "attachments_folder": "data/attachments", "auth_request_purge_schedule": "30 * * * * *", "authenticator_disable_time_drift": false, "data_folder": "data", "database_conn_init": "", "database_idle_timeout": 600, "database_max_conns": 10, "database_min_conns": 2, "database_timeout": 30, "database_url": "**********://**************************************************************************************************************", "db_connection_retries": 15, "disable_2fa_remember": false, "disable_admin_token": false, "disable_icon_download": false, "dns_prefer_ipv6": false, "domain": "*****://**********************", "domain_origin": "*****://**********************", "domain_path": "", "domain_set": true, "duo_context_purge_schedule": "30 * * * * *", "duo_host": null, "duo_ikey": null, "duo_skey": null, "duo_use_iframe": false, "email_2fa_auto_fallback": false, "email_2fa_enforce_on_verified_invite": false, "email_attempts_limit": 3, "email_change_allowed": true, "email_expiration_time": 600, "email_token_size": 6, "emergency_access_allowed": true, "emergency_notification_reminder_schedule": "0 3 * * * *", "emergency_request_timeout_schedule": "0 7 * * * *", "enable_db_wal": true, "enable_websocket": true, "enforce_single_org_with_reset_pw_policy": false, "event_cleanup_schedule": "0 10 0 * * *", "events_days_retain": null, "experimental_client_feature_flags": "", "extended_logging": true, "helo_name": null, "hibp_api_key": null, "http_request_block_non_global_ips": true, "http_request_block_regex": null, "icon_blacklist_non_global_ips": true, "icon_blacklist_regex": null, "icon_cache_folder": "data/icon_cache", "icon_cache_negttl": 259200, "icon_cache_ttl": 2592000, "icon_download_timeout": 10, "icon_redirect_code": 302, "icon_service": "internal", "incomplete_2fa_schedule": "30 * * * * *", "incomplete_2fa_time_limit": 3, "increase_note_size_limit": false, "invitation_expiration_hours": 120, "invitation_org_name": "Vaultwarden", "invitations_allowed": true, "ip_header": "X-Real-IP", "job_poll_interval_ms": 30000, "log_file": null, "log_level": "info", "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f", "login_ratelimit_max_burst": 10, "login_ratelimit_seconds": 60, "org_attachment_limit": null, "org_creation_users": "", "org_events_enabled": false, "org_groups_enabled": false, "password_hints_allowed": true, "password_iterations": 600000, "purge_incomplete_sso_auth": "0 20 0 * * *", "push_enabled": false, "push_identity_uri": "https://identity.bitwarden.com", "push_installation_id": "***", "push_installation_key": "***", "push_relay_uri": "https://push.bitwarden.com", "reload_templates": false, "require_device_email": false, "rsa_key_filename": "data/rsa_key", "send_purge_schedule": "0 5 * * * *", "sendmail_command": null, "sends_allowed": true, "sends_folder": "data/sends", "show_password_hint": false, "signups_allowed": true, "signups_domains_whitelist": "", "signups_verify": true, "signups_verify_resend_limit": 6, "signups_verify_resend_time": 3600, "smtp_accept_invalid_certs": false, "smtp_accept_invalid_hostnames": false, "smtp_auth_mechanism": null, "smtp_debug": false, "smtp_embed_images": true, "smtp_explicit_tls": null, "smtp_from": "******************", "smtp_from_name": "***************", "smtp_host": "***********", "smtp_password": "***", "smtp_port": 587, "smtp_security": "starttls", "smtp_ssl": null, "smtp_timeout": 15, "smtp_username": "***********", "sso_allow_unknown_email_verification": true, "sso_audience_trusted": null, "sso_auth_only_not_session": false, "sso_authority": "*****://*******************************************************************", "sso_authorize_extra_params": "", "sso_callback_path": "*****://***************************************************", "sso_client_cache_expiration": 0, "sso_client_id": "************************************", "sso_client_secret": "***", "sso_debug_tokens": false, "sso_enabled": true, "sso_master_password_policy": null, "sso_only": true, "sso_pkce": true, "sso_scopes": "email profile", "sso_signups_match_email": true, "templates_folder": "data/templates", "tmp_folder": "data/tmp", "trash_auto_delete_days": null, "trash_purge_schedule": "0 5 0 * * *", "use_sendmail": false, "use_syslog": false, "user_attachment_limit": null, "user_send_limit": null, "web_vault_enabled": true, "web_vault_folder": "web-vault/", "yubico_client_id": null, "yubico_secret_key": null, "yubico_server": null } ``` </details> ### Vaultwarden Build Version V1.35.7 ### Deployment method Official Container Image ### Custom deployment method It is deployed in kubernetes. Using gitlab as SOT and ArgoCD. ### Reverse Proxy no ### Host/Server Operating System Linux ### Operating System Version _No response_ ### Clients CLI, Web Vault ### Client Version Firefox v2026.2.0 ### Steps To Reproduce 1. Go to the login page. 2. Fill in an email address (SSO/Microsoft entraID from the organization) 3. Login 4. MFA 5. Returns back to login screen without any errors 6. Try again 7. Cry ### Expected Result Successful login using SSO. ### Actual Result A loop whereby the user is redirected to the login screen after finishing the MFA (microsoft authenticator) ### Logs ```text ``` ### Screenshots or Videos _No response_ ### Additional Context _No response_
GiteaMirror added the bug label 2026-06-17 09:50:40 -05:00
Author
Owner

@BlackDex commented on GitHub (Apr 22, 2026):

How is Vaultwarden deployed? As a Deployment or Statefulset?
And how many replica's, is the RSA key stored persistent?

Also, the logs of either the Browser, Vaultwarden or IdP should probably provide something useful, try setting the LOG_LEVEL of Vaultwarden to DEBUG and see if you get more details.

<!-- gh-comment-id:4296335248 --> @BlackDex commented on GitHub (Apr 22, 2026): How is Vaultwarden deployed? As a Deployment or Statefulset? And how many replica's, is the RSA key stored persistent? Also, the logs of either the Browser, Vaultwarden or IdP should probably provide something useful, try setting the `LOG_LEVEL` of Vaultwarden to `DEBUG` and see if you get more details.
Author
Owner

@TuotHash commented on GitHub (Apr 22, 2026):

I'm having the same issue, I'm also on pretty much the same setup.

when I try to sign up with SSO I get an unexpected Error, but the user is created in vaultwarden.
[2026-04-22 15:26:01.516][vaultwarden::api::identity][ERROR] Unable to refresh login credentials: Access token is close to expiration but we have no refresh token
[2026-04-22 15:26:01.517][response][INFO] (login) POST /identity/connect/token => 401 Unauthorized
In my IdP it seems everything worked and I get a Application authorized.

<!-- gh-comment-id:4296635599 --> @TuotHash commented on GitHub (Apr 22, 2026): I'm having the same issue, I'm also on pretty much the same setup. when I try to sign up with SSO I get an unexpected Error, but the user is created in vaultwarden. [2026-04-22 15:26:01.516][vaultwarden::api::identity][ERROR] Unable to refresh login credentials: Access token is close to expiration but we have no refresh token [2026-04-22 15:26:01.517][response][INFO] (login) POST /identity/connect/token => 401 Unauthorized In my IdP it seems everything worked and I get a Application authorized.
Author
Owner

@BlackDex commented on GitHub (Apr 22, 2026):

@Timshel any quick clues maybe?

<!-- gh-comment-id:4296764059 --> @BlackDex commented on GitHub (Apr 22, 2026): @Timshel any quick clues maybe?
Author
Owner

@stefan0xC commented on GitHub (Apr 22, 2026):

Given the configured SSO_SCOPES you probably did not follow the documentation: https://github.com/dani-garcia/vaultwarden/wiki/Enabling-SSO-support-using-OpenId-Connect#microsoft-entra-id

besides that I also think that also the sections about session handling could probably be improved as well (on the documentation page) given that this seems to be an recurring theme in user reported issues that seem to misunderstand how that works and what can be done about it (e.g. what the Bitwarden clients expect, how to adjust the token lifetime lengths and when to turn it off) because at the moment this info is a bit all over the documentation page and I'm not sure what is relevant in general and what is specific for a given identity provider...

<!-- gh-comment-id:4296894311 --> @stefan0xC commented on GitHub (Apr 22, 2026): Given the configured `SSO_SCOPES` you probably did not follow the documentation: https://github.com/dani-garcia/vaultwarden/wiki/Enabling-SSO-support-using-OpenId-Connect#microsoft-entra-id besides that I also think that also the sections about session handling could probably be improved as well (on the documentation page) given that this seems to be an recurring theme in user reported issues that seem to misunderstand how that works and what can be done about it (e.g. what the Bitwarden clients expect, how to adjust the token lifetime lengths and when to turn it off) because at the moment this info is a bit all over the documentation page and I'm not sure what is relevant in general and what is specific for a given identity provider...
Author
Owner

@TuotHash commented on GitHub (Apr 22, 2026):

Given the configured SSO_SCOPES you probably did not follow the documentation: https://github.com/dani-garcia/vaultwarden/wiki/Enabling-SSO-support-using-OpenId-Connect#microsoft-entra-id

Oh I did, but I didn‘t notice the sections further down.

Now I get this Error tho, but I'm unsure what to do. Why is beeing in the org required to log in?
[auth][ERROR] Unauthorized Error: The current user isn't member of the organization
[vaultwarden::api::core::organizations::_][WARN] Request guard OrgMemberHeaders failed: "The current user isn't member of the organization".
[auth][ERROR] Unauthorized Error: The current user isn't member of the organization
[response][INFO] (get_master_password_policy) GET /api/organizations/<org_id>/policies/master-password => 401 Unauthorized

<!-- gh-comment-id:4297093799 --> @TuotHash commented on GitHub (Apr 22, 2026): > Given the configured `SSO_SCOPES` you probably did not follow the documentation: https://github.com/dani-garcia/vaultwarden/wiki/Enabling-SSO-support-using-OpenId-Connect#microsoft-entra-id Oh I did, but I didn‘t notice the sections further down. Now I get this Error tho, but I'm unsure what to do. Why is beeing in the org required to log in? [auth][ERROR] Unauthorized Error: The current user isn't member of the organization [vaultwarden::api::core::organizations::_][WARN] Request guard `OrgMemberHeaders` failed: "The current user isn't member of the organization". [auth][ERROR] Unauthorized Error: The current user isn't member of the organization [response][INFO] (get_master_password_policy) GET /api/organizations/<org_id>/policies/master-password => 401 Unauthorized
Author
Owner

@Timshel commented on GitHub (Apr 22, 2026):

"Access token is close to expiration but we have no refresh token"

Is usually a sign that the provider require the offline_access scope. But for entra additional configuration need to be done on the provider side.

@stefan0xC for session handling there is some documentation, but I agree it's not the most discoverable.

@TuotHash I believe you are now hitting https://github.com/dani-garcia/vaultwarden/issues/7086 which is fixed in testing.

<!-- gh-comment-id:4297334496 --> @Timshel commented on GitHub (Apr 22, 2026): > "Access token is close to expiration but we have no refresh token" Is usually a sign that the provider require the `offline_access` scope. But for entra additional configuration need to be done on the provider side. @stefan0xC for session handling there is some [documentation](https://github.com/dani-garcia/vaultwarden/wiki/Enabling-SSO-support-using-OpenId-Connect#session-lifetime), but I agree it's not the most discoverable. @TuotHash I believe you are now hitting https://github.com/dani-garcia/vaultwarden/issues/7086 which is fixed in `testing`.
Author
Owner

@TuotHash commented on GitHub (Apr 22, 2026):

Damn I hope it's that, dunno what to do else, but I just updated from .4 to .7 today ;(

<!-- gh-comment-id:4297411634 --> @TuotHash commented on GitHub (Apr 22, 2026): Damn I hope it's that, dunno what to do else, but I just updated from .4 to .7 today ;(
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/vaultwarden#30112