Self-Hosted: SSO broken when using Authentik

(#597) Bug Fixed self-hosting

Thread

Comment by @nadd3r
RexSystem 1 vote originally by @nadd3r on GitHub OP
Seems its something else then. You sure you didn't miss something else in logs ? Also did you try forging a request yourself to authentik to see what it would answer from fluxer's container. Edit: Forgot to mention it but I have Authentik (2026.5.3) Also check that the field email_verified is set to true in authentik response (you can previsialize it in Provider settings) If no either create a Property Mapping or set the field true for you users.
I was originally running Authentik 2025.12.4 and have since updated to 2026.5.3. Looking at the logs from the Fluxer API container I can still see the following logs when trying to login with SSO:
api-1  | {"level":"info","time":"2026-06-17T16:59:51.138Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/start","status":200,"durationMs":7,"msg":"Request completed"}
api-1  | {"level":"info","time":"2026-06-17T16:59:51.547Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":6,"msg":"Request completed"}
api-1  | {"level":"info","time":"2026-06-17T16:59:53.345Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1192,"msg":"Request completed"}
However, if I go into Authentik and create a Property Mapping with the following information: Mapping Name: email_verified_true Scope Name: email Expression: return { "email": request.user.email, "email_verified": True } Then go into the Fluxer Provider and under Scopes swap out authentik default OAuth Mapping: OpenID 'email' with the created email_verified_true then try to login to Fluxer via SSO I can see the following in the Fluxer API logs:
api-1  | {"level":"info","time":"2026-06-17T17:03:16.503Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/start","status":200,"durationMs":6,"msg":"Request completed"}
api-1  | {"level":"info","time":"2026-06-17T17:03:16.894Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":7,"msg":"Request completed"}
api-1  | {"level":"info","time":"2026-06-17T17:03:18.708Z","service":"fluxer-api","env":"production","logger":"SsoService","email":"user@example.com","has_sub":true,"msg":"SSO login with sub claim"}
api-1  | {"level":"info","time":"2026-06-17T17:03:18.715Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":403,"durationMs":1231,"msg":"Request completed"}
I didn't see anything in the Authentik logs other than the typical authorization of the application. If there are any other logs I can provide to help troubleshoot this issue then please let me know what I should include or where to look.