When trying to use SSO to sign in with Authentik as the provider, Fluxer fails to login with the SSO user. Logs show a status code 400 when failing the login.
Client ID: <Client ID from Authentik>
Client Secret: <Client Secret from Authentik>
Scope: openid email profile
api-1 | {"level":"info","time":"2026-06-16T18:02:50.757Z","service":"fluxer-api","env":"production","method":"GET","path":"/.well-known/fluxer","status":200,"durationMs":3,"msg":"Request completed"}
app-proxy-1 | 2026-06-16T18:02:50.757980Z INFO fluxer_app_proxy::discovery_cache: discovery cache updated url="http://caddy:8088/api/.well-known/fluxer" api_code_version=unknown
api-1 | {"level":"info","time":"2026-06-16T18:02:52.449Z","service":"fluxer-api","env":"production","method":"POST","path":"/v1/auth/sso/complete","status":400,"durationMs":1131,"msg":"Request completed"}
worker-1 | {"level":"info","time":"2026-06-16T18:02:55.678Z","service":"fluxer-api","env":"production","workerId":"worker-batch-c124b7a9-67a4-4aaa-a1c3-1747e2641bad","lane":"batch","taskType":"syncUrlBlocklists","seq":1313,"redelivered":true,"msg":"Processing job"}
12 comments
Comment by @Nome200
https://auth.example.com/application/o/fluxer-test,https://auth.example.comandauth.example.com/application/o/fluxer-testdon't work. The message in the admin panel when saving could also print out the error instead of a green "Done.", but that's another issue.Comment by @TheUncleDolan
Comment by @Hudeler
https://example.com/works as expected buthttps://idp.example.com/causes theINVALID_FORM_BODY/INVALID_URL_FORMATerror and the config does not persist.Comment by @nadd3r
https://auth.example.com/application/o/fluxer/and everything saves but then fails silently with the400in the logs.Comment by @Buco7854
dnsdirective to your api service and set any public dns, you can also useextra_hoststo force resolving to your public IP instead. I dont think there is anyway to configure that behavior so for now I suppose having a public IP for your provider is required.Comment by @nadd3r
1.1.1.1and1.0.0.1set as the DNS servers and resolves Authentik to the public IP of the Cloudflare tunnel.Comment by @Buco7854
email_verifiedis set to true in authentik response (you can previsialize it in Provider settings) If no either create a Property Mapping or set the field true for you users.Comment by @nadd3r
email_verified_trueScope Name:emailExpression:return { "email": request.user.email, "email_verified": True }Then go into the Fluxer Provider and under Scopes swap outauthentik default OAuth Mapping: OpenID 'email'with the createdemail_verified_truethen try to login to Fluxer via SSO I can see the following in the Fluxer API logs:Comment by @Buco7854
Comment by @nadd3r
unauthenticatedfor the path `/application/o/fluxer/jwks/ so that may be the culprit here but I am not sure.Comment by @Buco7854
Comment by @nadd3r