Edit history

Earlier versions of Self-Hosted: SSO broken when using Authentik, newest first.

Current version | Edited by Rex
Changes
```Removed: ### ChecksRemoved: Removed: - ☑ I searched existing issues.Removed: - ☑ I wrote this report in my own words, except for direct translation if needed.Removed:
Show

Self-Hosted: SSO broken when using Authentik

Summary

When trying to use SSO to sign in with Authentik as the provider, Fluxer fails to login with the SSO user. Logs show a status code 400 when failing the login.

Steps to reproduce

  1. Install Fluxer
  2. In Authentik create Application and Provider with Strick redirect to https://chat.example.com/auth/sso/callback
  3. In Fluxer go to https://chat.example.com/admin/instance-config and fill out the SSO section.
Display Name: Authentik Issuer: https://auth.example.com/application/o/fluxer/ Authorization URL: https://auth.example.com/application/o/authorize/ Token URL: https://auth.example.com/application/o/token/ User Info URL: https://auth.example.com/application/o/userinfo/ JWKS URL: https://auth.example.com/application/o/fluxer/jwks/ Client ID: <Client ID from Authentik> Client Secret: <Client Secret from Authentik> Scope: openid email profile
  1. Save settings and try to login with SSO

Environment

Version: 149.0.7827.103 (Official Build) (64-bit) OS: Ubuntu Server 26.04

Logs or screenshots

api-1               | {"level":"info","time":"2026-06-16T18:02:50.757Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"}
app-proxy-1         | 2026-06-16T18:02:50.757980Z  INFO fluxer_app_proxy::discovery_cache: discovery cache updated url="http://caddy:8088/api/.well-known/fluxer" api_code_version=unknown
api-1               | {"level":"info","time":"2026-06-16T18:02:52.449Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1131,"msg":"Request completed"}
worker-1            | {"level":"info","time":"2026-06-16T18:02:55.678Z","service":"fluxer-api","env":"production","workerId":"worker-batch-c124b7a9-67a4-4aaa-a1c3-1747e2641bad","lane":"batch","taskType":"syncUrlBlocklists","seq":1313,"redelivered":true,"msg":"Processing job"}
Edited by Rex
Changes
api-1 | {"level":"info","time":"2026-06-16T18:02:52.449Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1131,"msg":"Request completed"}worker-1 | {"level":"info","time":"2026-06-16T18:02:55.678Z","service":"fluxer-api","env":"production","workerId":"worker-batch-c124b7a9-67a4-4aaa-a1c3-1747e2641bad","lane":"batch","taskType":"syncUrlBlocklists","seq":1313,"redelivered":true,"msg":"Processing job"}Added: ```### Checks
Show

Self-Hosted: SSO broken when using Authentik

Summary

When trying to use SSO to sign in with Authentik as the provider, Fluxer fails to login with the SSO user. Logs show a status code 400 when failing the login.

Steps to reproduce

  1. Install Fluxer
  2. In Authentik create Application and Provider with Strick redirect to https://chat.example.com/auth/sso/callback
  3. In Fluxer go to https://chat.example.com/admin/instance-config and fill out the SSO section.
Display Name: Authentik Issuer: https://auth.example.com/application/o/fluxer/ Authorization URL: https://auth.example.com/application/o/authorize/ Token URL: https://auth.example.com/application/o/token/ User Info URL: https://auth.example.com/application/o/userinfo/ JWKS URL: https://auth.example.com/application/o/fluxer/jwks/ Client ID: <Client ID from Authentik> Client Secret: <Client Secret from Authentik> Scope: openid email profile
  1. Save settings and try to login with SSO

Environment

Version: 149.0.7827.103 (Official Build) (64-bit) OS: Ubuntu Server 26.04

Logs or screenshots

api-1               | {"level":"info","time":"2026-06-16T18:02:50.757Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"}
app-proxy-1         | 2026-06-16T18:02:50.757980Z  INFO fluxer_app_proxy::discovery_cache: discovery cache updated url="http://caddy:8088/api/.well-known/fluxer" api_code_version=unknown
api-1               | {"level":"info","time":"2026-06-16T18:02:52.449Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1131,"msg":"Request completed"}
worker-1            | {"level":"info","time":"2026-06-16T18:02:55.678Z","service":"fluxer-api","env":"production","workerId":"worker-batch-c124b7a9-67a4-4aaa-a1c3-1747e2641bad","lane":"batch","taskType":"syncUrlBlocklists","seq":1313,"redelivered":true,"msg":"Processing job"}

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.
Edited by Rex
Changes
### Logs or screenshotsAdded: ```api-1 | {"level":"info","time":"2026-06-16T18:02:50.757Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"}app-proxy-1 | 2026-06-16T18:02:50.757980Z INFO fluxer_app_proxy::discovery_cache: discovery cache updated url="http://caddy:8088/api/.well-known/fluxer" api_code_version=unknown
Show

Self-Hosted: SSO broken when using Authentik

Summary

When trying to use SSO to sign in with Authentik as the provider, Fluxer fails to login with the SSO user. Logs show a status code 400 when failing the login.

Steps to reproduce

  1. Install Fluxer
  2. In Authentik create Application and Provider with Strick redirect to https://chat.example.com/auth/sso/callback
  3. In Fluxer go to https://chat.example.com/admin/instance-config and fill out the SSO section.
Display Name: Authentik Issuer: https://auth.example.com/application/o/fluxer/ Authorization URL: https://auth.example.com/application/o/authorize/ Token URL: https://auth.example.com/application/o/token/ User Info URL: https://auth.example.com/application/o/userinfo/ JWKS URL: https://auth.example.com/application/o/fluxer/jwks/ Client ID: <Client ID from Authentik> Client Secret: <Client Secret from Authentik> Scope: openid email profile
  1. Save settings and try to login with SSO

Environment

Version: 149.0.7827.103 (Official Build) (64-bit) OS: Ubuntu Server 26.04

Logs or screenshots

``` api-1 | {"level":"info","time":"2026-06-16T18:02:50.757Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"} app-proxy-1 | 2026-06-16T18:02:50.757980Z INFO fluxer_app_proxy::discovery_cache: discovery cache updated url="http://caddy:8088/api/.well-known/fluxer" api_code_version=unknown api-1 | {"level":"info","time":"2026-06-16T18:02:52.449Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1131,"msg":"Request completed"} worker-1 | {"level":"info","time":"2026-06-16T18:02:55.678Z","service":"fluxer-api","env":"production","workerId":"worker-batch-c124b7a9-67a4-4aaa-a1c3-1747e2641bad","lane":"batch","taskType":"syncUrlBlocklists","seq":1313,"redelivered":true,"msg":"Processing job"}

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.
Original by Rex
Show

Self-Hosted: SSO broken when using Authentik

Summary

When trying to use SSO to sign in with Authentik as the provider, Fluxer fails to login with the SSO user. Logs show a status code 400 when failing the login.

Steps to reproduce

  1. Install Fluxer
  2. In Authentik create Application and Provider with Strick redirect to https://chat.example.com/auth/sso/callback
  3. In Fluxer go to https://chat.example.com/admin/instance-config and fill out the SSO section.
Display Name: Authentik Issuer: https://auth.example.com/application/o/fluxer/ Authorization URL: https://auth.example.com/application/o/authorize/ Token URL: https://auth.example.com/application/o/token/ User Info URL: https://auth.example.com/application/o/userinfo/ JWKS URL: https://auth.example.com/application/o/fluxer/jwks/ Client ID: <Client ID from Authentik> Client Secret: <Client Secret from Authentik> Scope: openid email profile
  1. Save settings and try to login with SSO

Environment

Version: 149.0.7827.103 (Official Build) (64-bit) OS: Ubuntu Server 26.04

Logs or screenshots

api-1 | {"level":"info","time":"2026-06-16T18:02:50.757Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"} app-proxy-1 | 2026-06-16T18:02:50.757980Z INFO fluxer_app_proxy::discovery_cache: discovery cache updated url="http://caddy:8088/api/.well-known/fluxer" api_code_version=unknown api-1 | {"level":"info","time":"2026-06-16T18:02:52.449Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1131,"msg":"Request completed"} worker-1 | {"level":"info","time":"2026-06-16T18:02:55.678Z","service":"fluxer-api","env":"production","workerId":"worker-batch-c124b7a9-67a4-4aaa-a1c3-1747e2641bad","lane":"batch","taskType":"syncUrlBlocklists","seq":1313,"redelivered":true,"msg":"Processing job"}

Checks

  • ☑ I searched existing issues.
  • ☑ I wrote this report in my own words, except for direct translation if needed.