[GH-ISSUE #7216] SSO button not appearing in web after SSO_ENABLED=true #30139

Closed
opened 2026-06-17 09:53:26 -05:00 by GiteaMirror · 2 comments
Owner

Originally created by @gris-gris on GitHub (May 14, 2026).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7216

Prerequisites

Vaultwarden Support String

Your environment (Generated via diagnostics page)

  • Vaultwarden version: v1.36.0
  • Web-vault version: v2026.4.1
  • OS/Arch: linux/aarch64
  • Running within a container: true (Base: Alpine)
  • Database type: PostgreSQL
  • Database version: PostgreSQL 17.9 (Debian 17.9-1.pgdg12+1) on x86_64-pc-linux-gnu, compiled by gcc (Debian 12.2.0-14+deb12u1) 12.2.0, 64-bit
  • Uses config.json: false
  • Uses a reverse proxy: true
  • IP Header check: true (CF-Connecting-IP)
  • Internet access: true
  • Internet access via a proxy: false
  • DNS Check: true
  • TZ environment: Europe/Madrid
  • Browser/Server Time Check: true
  • Server/NTP Time Check: true
  • Domain Configuration Check: true
  • HTTPS Check: true
  • Websocket Check: true
  • HTTP Response Checks: true

Config & Details (Generated via diagnostics page)

Show Config & Details

Config:

{
  "_duo_akey": "***",
  "_enable_duo": true,
  "_enable_email_2fa": true,
  "_enable_smtp": true,
  "_enable_yubico": true,
  "_icon_service_csp": "https://icons.bitwarden.net/",
  "_icon_service_url": "https://icons.bitwarden.net/{}/icon.png",
  "_ip_header_enabled": true,
  "_max_note_size": 10000,
  "_smtp_img_src": "***:",
  "admin_ratelimit_max_burst": 3,
  "admin_ratelimit_seconds": 300,
  "admin_session_lifetime": 20,
  "admin_token": "***",
  "allowed_connect_src": "",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "/config/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": true,
  "data_folder": "data",
  "database_conn_init": "",
  "database_idle_timeout": 600,
  "database_max_conns": 10,
  "database_min_conns": 2,
  "database_timeout": 30,
  "database_url": "**********://***************************************************************************************************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "dns_prefer_ipv6": false,
  "domain": "*****://******************",
  "domain_origin": "*****://******************",
  "domain_path": "",
  "domain_set": true,
  "duo_context_purge_schedule": "30 * * * * *",
  "duo_host": "REDACTED.duosecurity.com",
  "duo_ikey": "REDACTED",
  "duo_skey": "***",
  "duo_use_iframe": false,
  "email_2fa_auto_fallback": false,
  "email_2fa_enforce_on_verified_invite": false,
  "email_attempts_limit": 3,
  "email_change_allowed": true,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": false,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "enable_websocket": true,
  "enforce_single_org_with_reset_pw_policy": false,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "ssh-agent,ssh-key-vault-item",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "http_request_block_non_global_ips": true,
  "http_request_block_regex": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "/config/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "bitwarden",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 3,
  "increase_note_size_limit": false,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "Vaultwarden",
  "invitations_allowed": true,
  "ip_header": "CF-Connecting-IP",
  "job_poll_interval_ms": 30000,
  "log_file": null,
  "log_level": "warn",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  "login_ratelimit_max_burst": 4,
  "login_ratelimit_seconds": 120,
  "org_attachment_limit": null,
  "org_creation_users": "",
  "org_events_enabled": true,
  "org_groups_enabled": true,
  "password_hints_allowed": false,
  "password_iterations": 600000,
  "purge_incomplete_sso_auth": "0 20 0 * * *",
  "push_enabled": true,
  "push_identity_uri": "https://identity.bitwarden.com",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://api.bitwarden.eu",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "/config/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "/config/sends",
  "show_password_hint": false,
  "signups_allowed": false,
  "signups_domains_whitelist": "",
  "signups_verify": false,
  "signups_verify_resend_limit": 6,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": null,
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": null,
  "smtp_from": "******************",
  "smtp_from_name": "***********",
  "smtp_host": "*****************",
  "smtp_password": "***",
  "smtp_port": 465,
  "smtp_security": "force_tls",
  "smtp_ssl": null,
  "smtp_timeout": 15,
  "smtp_username": "********************************",
  "sso_allow_unknown_email_verification": false,
  "sso_audience_trusted": null,
  "sso_auth_only_not_session": false,
  "sso_authority": "*****://*******************",
  "sso_authorize_extra_params": "",
  "sso_callback_path": "*****://***********************************************",
  "sso_client_cache_expiration": 0,
  "sso_client_id": "************************************",
  "sso_client_secret": "***",
  "sso_debug_tokens": false,
  "sso_enabled": true,
  "sso_master_password_policy": null,
  "sso_only": false,
  "sso_pkce": true,
  "sso_scopes": "email profile groups offline_access",
  "sso_signups_match_email": true,
  "templates_folder": "data/templates",
  "tmp_folder": "/config/tmp",
  "trash_auto_delete_days": null,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "yubico_client_id": "REDACTED",
  "yubico_secret_key": "***",
  "yubico_server": null
}

Vaultwarden Build Version

v1.36.0

Deployment method

Official Container Image

Custom deployment method

No response

Reverse Proxy

caddy:2

Host/Server Operating System

Linux

Operating System Version

Ubuntu 22.04

Clients

Web Vault

Client Version

2026.4.1

Steps To Reproduce

  1. Enable SSO by setting ENV variables:
SSO_ONLY=false
SSO_CLIENT_SECRET=REDACTED
SSO_ENABLED=true
SSO_SIGNUPS_MATCH_EMAIL=true
SSO_CLIENT_ID=REDACTED
SSO_AUTHORITY=https://REDACTED.net
SSO_SCOPES=email profile groups offline_access
SSO_PKCE=true
  1. Go to Web vault
  2. No button for OIDC entry, only email:
Screenshot Image

Expected Result

  1. Button for SSO appear and work as intended

Actual Result

  1. No button appear
  2. /identity/connect/oidc-signin responding with 404 as well

Logs

vaultwarden  | /--------------------------------------------------------------------\
vaultwarden  | |                        Starting Vaultwarden                        |
vaultwarden  | |                           Version 1.36.0                           |
vaultwarden  | |--------------------------------------------------------------------|
vaultwarden  | | This is an *unofficial* Bitwarden implementation, DO NOT use the   |
vaultwarden  | | official channels to report bugs/features, regardless of client.   |
vaultwarden  | | Send usage/configuration questions or feature requests to:         |
vaultwarden  | |   https://github.com/dani-garcia/vaultwarden/discussions or        |
vaultwarden  | |   https://vaultwarden.discourse.group/                             |
vaultwarden  | | Report suspected bugs/issues in the software itself at:            |
vaultwarden  | |   https://github.com/dani-garcia/vaultwarden/issues/new            |
vaultwarden  | \--------------------------------------------------------------------/
vaultwarden  |
vaultwarden  | [INFO] Using saved config from `data/config.json` for configuration.
vaultwarden  |
vaultwarden  | [2026-05-14 05:01:35.787][error][ERROR] 2FA token not provided
vaultwarden  | [2026-05-14 05:10:58.262][vaultwarden::api::admin][ERROR] Testing error 404 response
vaultwarden  | [2026-05-14 05:10:58.264][vaultwarden::api::admin][ERROR] Testing error 403 response
vaultwarden  | [2026-05-14 05:10:58.264][vaultwarden::api::admin][ERROR] Testing error 400 response
vaultwarden  | [2026-05-14 05:10:58.266][vaultwarden::api::admin][ERROR] Testing error 401 response
vaultwarden  | [2026-05-14 05:18:00.348][vaultwarden::api::identity::_][WARN] Query string failed to match route declaration.
vaultwarden  | [2026-05-14 05:18:00.348][vaultwarden::api::identity::_][WARN] missing
vaultwarden  | [2026-05-14 05:18:00.348][vaultwarden::api::identity::_][WARN] missing
vaultwarden  | [2026-05-14 05:18:00.380][vaultwarden::api::identity::_][WARN] Query string failed to match route declaration.
vaultwarden  | [2026-05-14 05:18:00.380][vaultwarden::api::identity::_][WARN] missing
vaultwarden  | [2026-05-14 05:18:00.381][vaultwarden::api::identity::_][WARN] missing

Screenshots or Videos

Image

Additional Context

No response

Originally created by @gris-gris on GitHub (May 14, 2026). Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7216 ### Prerequisites - [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=) - [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/) ### Vaultwarden Support String ### Your environment (Generated via diagnostics page) * Vaultwarden version: v1.36.0 * Web-vault version: v2026.4.1 * OS/Arch: linux/aarch64 * Running within a container: true (Base: Alpine) * Database type: PostgreSQL * Database version: PostgreSQL 17.9 (Debian 17.9-1.pgdg12+1) on x86_64-pc-linux-gnu, compiled by gcc (Debian 12.2.0-14+deb12u1) 12.2.0, 64-bit * Uses config.json: false * Uses a reverse proxy: true * IP Header check: true (CF-Connecting-IP) * Internet access: true * Internet access via a proxy: false * DNS Check: true * TZ environment: Europe/Madrid * Browser/Server Time Check: true * Server/NTP Time Check: true * Domain Configuration Check: true * HTTPS Check: true * Websocket Check: true * HTTP Response Checks: true ### Config & Details (Generated via diagnostics page) <details><summary>Show Config & Details</summary> **Config:** ```json { "_duo_akey": "***", "_enable_duo": true, "_enable_email_2fa": true, "_enable_smtp": true, "_enable_yubico": true, "_icon_service_csp": "https://icons.bitwarden.net/", "_icon_service_url": "https://icons.bitwarden.net/{}/icon.png", "_ip_header_enabled": true, "_max_note_size": 10000, "_smtp_img_src": "***:", "admin_ratelimit_max_burst": 3, "admin_ratelimit_seconds": 300, "admin_session_lifetime": 20, "admin_token": "***", "allowed_connect_src": "", "allowed_iframe_ancestors": "", "attachments_folder": "/config/attachments", "auth_request_purge_schedule": "30 * * * * *", "authenticator_disable_time_drift": true, "data_folder": "data", "database_conn_init": "", "database_idle_timeout": 600, "database_max_conns": 10, "database_min_conns": 2, "database_timeout": 30, "database_url": "**********://***************************************************************************************************", "db_connection_retries": 15, "disable_2fa_remember": false, "disable_admin_token": false, "disable_icon_download": false, "dns_prefer_ipv6": false, "domain": "*****://******************", "domain_origin": "*****://******************", "domain_path": "", "domain_set": true, "duo_context_purge_schedule": "30 * * * * *", "duo_host": "REDACTED.duosecurity.com", "duo_ikey": "REDACTED", "duo_skey": "***", "duo_use_iframe": false, "email_2fa_auto_fallback": false, "email_2fa_enforce_on_verified_invite": false, "email_attempts_limit": 3, "email_change_allowed": true, "email_expiration_time": 600, "email_token_size": 6, "emergency_access_allowed": false, "emergency_notification_reminder_schedule": "0 3 * * * *", "emergency_request_timeout_schedule": "0 7 * * * *", "enable_db_wal": true, "enable_websocket": true, "enforce_single_org_with_reset_pw_policy": false, "event_cleanup_schedule": "0 10 0 * * *", "events_days_retain": null, "experimental_client_feature_flags": "ssh-agent,ssh-key-vault-item", "extended_logging": true, "helo_name": null, "hibp_api_key": null, "http_request_block_non_global_ips": true, "http_request_block_regex": null, "icon_blacklist_non_global_ips": true, "icon_blacklist_regex": null, "icon_cache_folder": "/config/icon_cache", "icon_cache_negttl": 259200, "icon_cache_ttl": 2592000, "icon_download_timeout": 10, "icon_redirect_code": 302, "icon_service": "bitwarden", "incomplete_2fa_schedule": "30 * * * * *", "incomplete_2fa_time_limit": 3, "increase_note_size_limit": false, "invitation_expiration_hours": 120, "invitation_org_name": "Vaultwarden", "invitations_allowed": true, "ip_header": "CF-Connecting-IP", "job_poll_interval_ms": 30000, "log_file": null, "log_level": "warn", "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f", "login_ratelimit_max_burst": 4, "login_ratelimit_seconds": 120, "org_attachment_limit": null, "org_creation_users": "", "org_events_enabled": true, "org_groups_enabled": true, "password_hints_allowed": false, "password_iterations": 600000, "purge_incomplete_sso_auth": "0 20 0 * * *", "push_enabled": true, "push_identity_uri": "https://identity.bitwarden.com", "push_installation_id": "***", "push_installation_key": "***", "push_relay_uri": "https://api.bitwarden.eu", "reload_templates": false, "require_device_email": false, "rsa_key_filename": "/config/rsa_key", "send_purge_schedule": "0 5 * * * *", "sendmail_command": null, "sends_allowed": true, "sends_folder": "/config/sends", "show_password_hint": false, "signups_allowed": false, "signups_domains_whitelist": "", "signups_verify": false, "signups_verify_resend_limit": 6, "signups_verify_resend_time": 3600, "smtp_accept_invalid_certs": false, "smtp_accept_invalid_hostnames": false, "smtp_auth_mechanism": null, "smtp_debug": false, "smtp_embed_images": true, "smtp_explicit_tls": null, "smtp_from": "******************", "smtp_from_name": "***********", "smtp_host": "*****************", "smtp_password": "***", "smtp_port": 465, "smtp_security": "force_tls", "smtp_ssl": null, "smtp_timeout": 15, "smtp_username": "********************************", "sso_allow_unknown_email_verification": false, "sso_audience_trusted": null, "sso_auth_only_not_session": false, "sso_authority": "*****://*******************", "sso_authorize_extra_params": "", "sso_callback_path": "*****://***********************************************", "sso_client_cache_expiration": 0, "sso_client_id": "************************************", "sso_client_secret": "***", "sso_debug_tokens": false, "sso_enabled": true, "sso_master_password_policy": null, "sso_only": false, "sso_pkce": true, "sso_scopes": "email profile groups offline_access", "sso_signups_match_email": true, "templates_folder": "data/templates", "tmp_folder": "/config/tmp", "trash_auto_delete_days": null, "trash_purge_schedule": "0 5 0 * * *", "use_sendmail": false, "use_syslog": false, "user_attachment_limit": null, "user_send_limit": null, "web_vault_enabled": true, "web_vault_folder": "web-vault/", "yubico_client_id": "REDACTED", "yubico_secret_key": "***", "yubico_server": null } ``` </details> ### Vaultwarden Build Version v1.36.0 ### Deployment method Official Container Image ### Custom deployment method _No response_ ### Reverse Proxy caddy:2 ### Host/Server Operating System Linux ### Operating System Version Ubuntu 22.04 ### Clients Web Vault ### Client Version 2026.4.1 ### Steps To Reproduce 1. Enable SSO by setting ENV variables: ``` SSO_ONLY=false SSO_CLIENT_SECRET=REDACTED SSO_ENABLED=true SSO_SIGNUPS_MATCH_EMAIL=true SSO_CLIENT_ID=REDACTED SSO_AUTHORITY=https://REDACTED.net SSO_SCOPES=email profile groups offline_access SSO_PKCE=true ``` 2. Go to Web vault 3. No button for OIDC entry, only email: <details><summary>Screenshot</summary> <img width="1053" height="725" alt="Image" src="https://github.com/user-attachments/assets/274ea2a9-846b-4e97-b64e-165f43b90aac" /> </details> ### Expected Result 1. Button for SSO appear and work as intended ### Actual Result 1. No button appear 2. /identity/connect/oidc-signin responding with 404 as well ### Logs ```text vaultwarden | /--------------------------------------------------------------------\ vaultwarden | | Starting Vaultwarden | vaultwarden | | Version 1.36.0 | vaultwarden | |--------------------------------------------------------------------| vaultwarden | | This is an *unofficial* Bitwarden implementation, DO NOT use the | vaultwarden | | official channels to report bugs/features, regardless of client. | vaultwarden | | Send usage/configuration questions or feature requests to: | vaultwarden | | https://github.com/dani-garcia/vaultwarden/discussions or | vaultwarden | | https://vaultwarden.discourse.group/ | vaultwarden | | Report suspected bugs/issues in the software itself at: | vaultwarden | | https://github.com/dani-garcia/vaultwarden/issues/new | vaultwarden | \--------------------------------------------------------------------/ vaultwarden | vaultwarden | [INFO] Using saved config from `data/config.json` for configuration. vaultwarden | vaultwarden | [2026-05-14 05:01:35.787][error][ERROR] 2FA token not provided vaultwarden | [2026-05-14 05:10:58.262][vaultwarden::api::admin][ERROR] Testing error 404 response vaultwarden | [2026-05-14 05:10:58.264][vaultwarden::api::admin][ERROR] Testing error 403 response vaultwarden | [2026-05-14 05:10:58.264][vaultwarden::api::admin][ERROR] Testing error 400 response vaultwarden | [2026-05-14 05:10:58.266][vaultwarden::api::admin][ERROR] Testing error 401 response vaultwarden | [2026-05-14 05:18:00.348][vaultwarden::api::identity::_][WARN] Query string failed to match route declaration. vaultwarden | [2026-05-14 05:18:00.348][vaultwarden::api::identity::_][WARN] missing vaultwarden | [2026-05-14 05:18:00.348][vaultwarden::api::identity::_][WARN] missing vaultwarden | [2026-05-14 05:18:00.380][vaultwarden::api::identity::_][WARN] Query string failed to match route declaration. vaultwarden | [2026-05-14 05:18:00.380][vaultwarden::api::identity::_][WARN] missing vaultwarden | [2026-05-14 05:18:00.381][vaultwarden::api::identity::_][WARN] missing ``` ### Screenshots or Videos <img width="1053" height="725" alt="Image" src="https://github.com/user-attachments/assets/274ea2a9-846b-4e97-b64e-165f43b90aac" /> ### Additional Context _No response_
GiteaMirror added the bug label 2026-06-17 09:53:26 -05:00
Author
Owner

@stefan0xC commented on GitHub (May 14, 2026):

1. No button appear

Can you force-reload the /css/vaultwarden.css file (and make sure it is not cached by a reverse proxy, etc.)

2. /identity/connect/oidc-signin responding with 404 as well

The callback path is not meant to be opened directly.
If you want to test if login with SSO works even if the button is not visible you can open /#/sso, enter something like test and check if you are redirected to your identity provider or get this error:
Image

<!-- gh-comment-id:4447242644 --> @stefan0xC commented on GitHub (May 14, 2026): > 1. No button appear > Can you force-reload the `/css/vaultwarden.css` file (and make sure it is not cached by a reverse proxy, etc.) > 2. /identity/connect/oidc-signin responding with 404 as well > The callback path is not meant to be opened directly. If you want to test if login with SSO works even if the button is not visible you can open `/#/sso`, enter something like `test` and check if you are redirected to your identity provider or get this error: <img width="393" height="85" alt="Image" src="https://github.com/user-attachments/assets/25dc46ae-c113-4b4b-b8b5-a938b8fa6590" />
Author
Owner

@gris-gris commented on GitHub (May 14, 2026):

I'm very sorry, forgot to clear the cache on Cloudflare side, closing the issue

<!-- gh-comment-id:4447447827 --> @gris-gris commented on GitHub (May 14, 2026): I'm very sorry, forgot to clear the cache on Cloudflare side, closing the issue
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/vaultwarden#30139