# SSO

**URL:** https://meta.discourse.org/c/support/sso/24.md

[Latest](https://meta.discourse.org/latest.md) · [Categories](https://meta.discourse.org/categories.md) · [Tags](https://meta.discourse.org/tags.md)

---

## [About the SSO category](https://meta.discourse.org/t/about-the-sso-category/13110)

<div class="topic-metadata">

**Author:** [@Discourse](https://meta.discourse.org/u/Discourse)\
**Replies:** 0\
**Last updated:** [February 26, 2014, 9:36pm UTC](https://meta.discourse.org/t/about-the-sso-category/13110 "2014-02-26T21:36:48Z")

</div>

For queries specifically about SSO (single sign-on) and login using third-party providers (Google, Facebook, GitHub etc). See the official documentation on DiscourseConnect SSO.

---

## [Best approach to SSO with Ghost?](https://meta.discourse.org/t/best-approach-to-sso-with-ghost/266342)

<div class="topic-metadata">

**Author:** [@satonotdead](https://meta.discourse.org/u/satonotdead)\
**Replies:** 1\
**Last updated:** [September 10, 2026, 10:27pm UTC](https://meta.discourse.org/t/best-approach-to-sso-with-ghost/266342 "2026-09-10T22:27:13Z")

</div>

I’ve noticed some updated apps (SAML and OpenID) and I’m curious about the best approach to enable SSO within Discourse and Ghost. At the moment, I’m searching for a 2-way-sync solution to maintain consistent tier level…

---

## [Connect User logins from my Wix site for my Discourse forum](https://meta.discourse.org/t/connect-user-logins-from-my-wix-site-for-my-discourse-forum/407636)

<div class="topic-metadata">

**Author:** [@Gid](https://meta.discourse.org/u/Gid)\
**Replies:** 12\
**Last updated:** [July 16, 2026, 4:19am UTC](https://meta.discourse.org/t/connect-user-logins-from-my-wix-site-for-my-discourse-forum/407636 "2026-07-16T04:19:58Z")

</div>

I have a Wix website on a paid plan (Core). The site’s members (people who’ve just signed up on my site) are well integrated into it, with their details & connections are stored on Wix’s powerful CMSs. So my Wix site is…

---

## [CSRFTokenVerifier::InvalidCSRFToken when initiating SAML login on Discourse 2026.6](https://meta.discourse.org/t/csrftokenverifier-invalidcsrftoken-when-initiating-saml-login-on-discourse-2026-6/406986)

<div class="topic-metadata">

**Author:** [@Osman\_Nuri\_Mermer](https://meta.discourse.org/u/Osman_Nuri_Mermer)\
**Replies:** 0\
**Last updated:** [July 7, 2026, 2:57pm UTC](https://meta.discourse.org/t/csrftokenverifier-invalidcsrftoken-when-initiating-saml-login-on-discourse-2026-6/406986 "2026-07-07T14:57:12Z")

</div>

CSRFTokenVerifier::InvalidCSRFToken when initiating SAML login on Discourse 2026.6 Hi, I’m trying to configure SAML authentication with ADFS on a fresh Discourse installation. Environment Discourse version: 2026.6 (R…

---

## [Best practice for moving users away from institutional email domains while avoiding duplicate/impersonation accounts](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 2\
**Last updated:** [June 17, 2026, 1:54pm UTC](https://meta.discourse.org/t/best-practice-for-moving-users-away-from-institutional-email-domains-while-avoiding-duplicate-impersonation-accounts/405143 "2026-06-17T13:54:10Z")

</div>

I run an independent Discourse community https://physicswithethan.discourse.diy which previously allowed institutional email addresses and external SSO. I now want to move toward ordinary local Discourse accounts using …

---

## [How to deploy a SSO bridge alongside a discourse\_docker deployment?](https://meta.discourse.org/t/how-to-deploy-a-sso-bridge-alongside-a-discourse-docker-deployment/110003)

<div class="topic-metadata">

**Author:** [@consideRatio](https://meta.discourse.org/u/consideRatio)\
**Replies:** 7\
**Last updated:** [April 26, 2026, 8:05pm UTC](https://meta.discourse.org/t/how-to-deploy-a-sso-bridge-alongside-a-discourse-docker-deployment/110003 "2026-04-26T20:05:49Z")

</div>

I realized I wanted to develop and deploy a Discourse SSO endpoint that wraps authentication to a OIDC provider. The endpoint is now developed as a Flask application available as a PyPI package: discourse-sso-oidc-bridge…

---

## [How is it possible to connect Discourse with two OIDC providers?](https://meta.discourse.org/t/how-is-it-possible-to-connect-discourse-with-two-oidc-providers/304280)

<div class="topic-metadata">

**Author:** [@sebix1](https://meta.discourse.org/u/sebix1)\
**Replies:** 3\
**Last updated:** [April 25, 2026, 8:06am UTC](https://meta.discourse.org/t/how-is-it-possible-to-connect-discourse-with-two-oidc-providers/304280 "2026-04-25T08:06:47Z")

</div>

I managed to connect GitLab and Microsoft (Azure) with this plugin. btw: for the Azure AD service, make sure to use the “Application Client ID” as client id, not the secret ID or value). How is it possible to connect Di…

---

## [Forum cannot recognize alternate email from Discourse ID](https://meta.discourse.org/t/discourse-id/398181)

<div class="topic-metadata">

**Author:** [@25w31b](https://meta.discourse.org/u/25w31b)\
**Replies:** 2\
**Last updated:** [March 28, 2026, 11:19am UTC](https://meta.discourse.org/t/discourse-id/398181 "2026-03-28T11:19:56Z")

</div>

When I log in or register on the forum using Discourse ID, the forum only recognizes the primary email and not the secondary email. On regular forums (like this Discourse Meta), the secondary email needs to be added manually, but on free-hosted forums, I cannot manually add or change the email address because the forum displays a 404 error when I try to verify the email address.

---

## [How to enable sso on discourse?](https://meta.discourse.org/t/how-to-enable-sso-on-discourse/397816)

<div class="topic-metadata">

**Author:** [@Abhishek\_Soni](https://meta.discourse.org/u/Abhishek_Soni)\
**Replies:** 4\
**Last updated:** [March 7, 2026, 10:05am UTC](https://meta.discourse.org/t/how-to-enable-sso-on-discourse/397816 "2026-03-07T10:05:59Z")

</div>

I have hosted the discourse on my server, now i want to enable sso login (l have a website from where i want to redirect to discourse), but i can’t find option to enable sso.

---

## [Connect Discourse Auth with my Django user DB?](https://meta.discourse.org/t/connect-discourse-auth-with-my-django-user-db/147604)

<div class="topic-metadata">

**Author:** [@funfake](https://meta.discourse.org/u/funfake)\
**Replies:** 6\
**Last updated:** [February 12, 2026, 4:43am UTC](https://meta.discourse.org/t/connect-discourse-auth-with-my-django-user-db/147604 "2026-02-12T04:43:11Z")

</div>

Hi ! I’m really interested in Discourse for my ecommerce platform. It would provide a great helping section for my users. I’ve seen that Discourse has it’s own Auth methods. I was wondering if I could modify these in o…

---

## [I’m seeing OIDC failures in Discourse logs: \`CSRFTokenVerifier::InvalidCSRFToken\` on \`/auth/oidc\` (POST)](https://meta.discourse.org/t/i-m-seeing-oidc-failures-in-discourse-logs-csrftokenverifier-invalidcsrftoken-on-auth-oidc-post/395752)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 0\
**Last updated:** [February 11, 2026, 7:26am UTC](https://meta.discourse.org/t/i-m-seeing-oidc-failures-in-discourse-logs-csrftokenverifier-invalidcsrftoken-on-auth-oidc-post/395752 "2026-02-11T07:26:07Z")

</div>

Hi all, I’m running Discourse 2026.2.0-latest (26f3e2aa87) (Docker install, default nginx template, no Cloudflare). I have OpenID Connect enabled (Microsoft Entra / Azure AD). When a user tries to sign up / log in via…

---

## [OIDC csrf\_detected can mask user cancel / consent rejection - docs could clarify log inspection](https://meta.discourse.org/t/oidc-csrf-detected-can-mask-user-cancel-consent-rejection-docs-could-clarify-log-inspection/395021)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 1\
**Last updated:** [February 5, 2026, 9:16pm UTC](https://meta.discourse.org/t/oidc-csrf-detected-can-mask-user-cancel-consent-rejection-docs-could-clarify-log-inspection/395021 "2026-02-05T21:16:57Z")

</div>

Continuing the discussion from OIDC login via Discourse iOS app occasionally fails with csrf\_detected on callback: Hi all, This is a follow-up observation linked to my earlier thread about OIDC login failures initiated…

---

## [Lapsed members in CRM not removed via Discourse Connect](https://meta.discourse.org/t/lapsed-members-in-crm-not-removed-via-discourse-connect/395317)

<div class="topic-metadata">

**Author:** [@HBuckley](https://meta.discourse.org/u/HBuckley)\
**Replies:** 0\
**Last updated:** [February 5, 2026, 8:24pm UTC](https://meta.discourse.org/t/lapsed-members-in-crm-not-removed-via-discourse-connect/395317 "2026-02-05T20:24:36Z")

</div>

Hi! We have integrated our membership CRM (Sheep) using Discourse Connect. However, when a member lapses or cancels, it doesn’t look as though their access to Discourse will automatically be removed. How can we make this…

---

## [New users clicking category link see “access to this forum is by invite only” and cannot log in via OAuth2](https://meta.discourse.org/t/new-users-clicking-category-link-see-access-to-this-forum-is-by-invite-only-and-cannot-log-in-via-oauth2/389937)

<div class="topic-metadata">

**Author:** [@Soumya\_Ranjan\_Mishra](https://meta.discourse.org/u/Soumya_Ranjan_Mishra)\
**Replies:** 4\
**Last updated:** [February 5, 2026, 5:38pm UTC](https://meta.discourse.org/t/new-users-clicking-category-link-see-access-to-this-forum-is-by-invite-only-and-cannot-log-in-via-oauth2/389937 "2026-02-05T17:38:34Z")

</div>

Hi Everyone, We have a private category in our Discourse instance that is restricted to a specific user group. We created a link so new users can access this category after logging in through OAuth2. However, when new …

---

## [OIDC login via Discourse iOS app occasionally fails with csrf\_detected on callback](https://meta.discourse.org/t/oidc-login-via-discourse-ios-app-occasionally-fails-with-csrf-detected-on-callback/394838)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 4\
**Last updated:** [February 2, 2026, 8:46pm UTC](https://meta.discourse.org/t/oidc-login-via-discourse-ios-app-occasionally-fails-with-csrf-detected-on-callback/394838 "2026-02-02T20:46:42Z")

</div>

Hi, I’m running Discourse ( 2026.2.0-latest (f7cec86997))with OpenID Connect (Azure / Entra ID as IdP). I’ve noticed an occasional login failure that only seems to occur when users attempt to sign in via the Discourse …

---

## [Settings for oauth2, IP rejected, how to solve](https://meta.discourse.org/t/oauth2-ip/394318)

<div class="topic-metadata">

**Author:** [@青岛王斌](https://meta.discourse.org/u/%E9%9D%92%E5%B2%9B%E7%8E%8B%E6%96%8C)\
**Replies:** 1\
**Last updated:** [January 26, 2026, 10:44am UTC](https://meta.discourse.org/t/oauth2-ip/394318 "2026-01-26T10:44:36Z")

</div>

\[root@HDDXVZ4023 discourse\_docker\]# tail -f /var/discourse/shared/standalone/log/rails/production.log Body: client\_id: client\_secret: grant\_type: authorization\_code code: zeyHxfhcvSIzMiw :redirect\_uri: https://\*\*\*\*\*…

---

## [SSO - User Roles or ACLs to differentiate access levels](https://meta.discourse.org/t/sso-user-roles-or-acls-to-differentiate-access-levels/394229)

<div class="topic-metadata">

**Author:** [@Drancis](https://meta.discourse.org/u/Drancis)\
**Replies:** 2\
**Last updated:** [January 24, 2026, 12:25am UTC](https://meta.discourse.org/t/sso-user-roles-or-acls-to-differentiate-access-levels/394229 "2026-01-24T00:25:26Z")

</div>

Hi We are leveraging SSO for our community authentication. Within our system we have different customers, let’s just say A and B. We want to distinguish these groups in Discourse so that we have private Categories. In…

---

## [500 error after getting the token in oauth2-basic plugin](https://meta.discourse.org/t/500-error-after-getting-the-token-in-oauth2-basic-plugin/392974)

<div class="topic-metadata">

**Author:** [@tejasj654](https://meta.discourse.org/u/tejasj654)\
**Replies:** 1\
**Last updated:** [January 8, 2026, 2:40pm UTC](https://meta.discourse.org/t/500-error-after-getting-the-token-in-oauth2-basic-plugin/392974 "2026-01-08T14:40:32Z")

</div>

I am facing a weird error that others seem to have solved. Basically, I am getting the token from the API but no user details API calls are being made. Instead, the callback URL fails with 500 without any error message. …

---

## [Social Login only works on desktop, but not on mobile devices (CSRF detected)](https://meta.discourse.org/t/social-login-funktioniert-nur-auf-desktop-aber-nicht-auf-mobilen-geraten-csrf-detected/389975)

<div class="topic-metadata">

**Author:** [@DW\_dev](https://meta.discourse.org/u/DW_dev)\
**Replies:** 3\
**Last updated:** [November 30, 2025, 7:13pm UTC](https://meta.discourse.org/t/social-login-funktioniert-nur-auf-desktop-aber-nicht-auf-mobilen-geraten-csrf-detected/389975 "2025-11-30T19:13:29Z")

</div>

Hello, My Discourse forum has a problem with social logins (Google, Discord, LinkedIn): On desktop, all social logins work perfectly. On all mobile devices (iOS/Android, Safari/Chrome/Firefox) it s...

---

## [Invite only forum with Google, OIDC or Oauth2 login](https://meta.discourse.org/t/invite-only-forum-with-google-oidc-or-oauth2-login/387802)

<div class="topic-metadata">

**Author:** [@phil22](https://meta.discourse.org/u/phil22)\
**Replies:** 2\
**Last updated:** [November 12, 2025, 10:43am UTC](https://meta.discourse.org/t/invite-only-forum-with-google-oidc-or-oauth2-login/387802 "2025-11-12T10:43:57Z")

</div>

Hello, I have a self hosted discourse instance. I have set up the OIDC connect plugin to sign in users with their google account. Using the settings in the google cloud console I’m able to limit this to users within my …

---

## [SSO update avatar\_url is always invalid](https://meta.discourse.org/t/sso-update-avatar-url-is-always-invalid/386950)

<div class="topic-metadata">

**Author:** [@wangya123](https://meta.discourse.org/u/wangya123)\
**Replies:** 1\
**Last updated:** [October 29, 2025, 12:15pm UTC](https://meta.discourse.org/t/sso-update-avatar-url-is-always-invalid/386950 "2025-10-29T12:15:26Z")

</div>

I set the avatar\_force\_update parameter to true， Discourse Connect overrides avatar is also checked，Discourse Connect overrides avatar I also tried not to check it, but still can’t update the avatar The avatar…

---

## [Discourse connect avatar\_url isn't working](https://meta.discourse.org/t/discourse-connect-avatar-url-isnt-working/293036)

<div class="topic-metadata">

**Author:** [@Viktors\_Vradijs](https://meta.discourse.org/u/Viktors_Vradijs)\
**Replies:** 9\
**Last updated:** [October 29, 2025, 6:58am UTC](https://meta.discourse.org/t/discourse-connect-avatar-url-isnt-working/293036 "2025-10-29T06:58:33Z")

</div>

Hi. Have faced issue with avatar update through discourse-connect. In sso payload is avarat\_force\_update = true and avatar\_url = https://files.ekool.eu/ekool/202311/3011/00/-m-ae103b0bac1fa5fc3cb65217a0183ba7b2633edae6d…

---

## [How to enable discourse id login in my site](https://meta.discourse.org/t/how-to-enable-discourse-id-login-in-my-site/386716)

<div class="topic-metadata">

**Author:** [@whitewaterdeu](https://meta.discourse.org/u/whitewaterdeu)\
**Replies:** 3\
**Last updated:** [October 26, 2025, 4:13pm UTC](https://meta.discourse.org/t/how-to-enable-discourse-id-login-in-my-site/386716 "2025-10-26T16:13:03Z")

</div>

i want to open this function to allow users login by Discourse ID but i don’t know how to enable discourse id login in my site Discourse ID is now available. Try it today!

---

## [Discourse ID fails to activate on my instance](https://meta.discourse.org/t/discourse-id-fails-to-activate-on-my-instance/386023)

<div class="topic-metadata">

**Author:** [@Thomas\_Rother](https://meta.discourse.org/u/Thomas_Rother)\
**Replies:** 26\
**Last updated:** [October 22, 2025, 5:00pm UTC](https://meta.discourse.org/t/discourse-id-fails-to-activate-on-my-instance/386023 "2025-10-22T17:00:39Z")

</div>

I see this message when I try to activate Discourse\_id on my test system (3.6.0.beta2-latest): enable\_discourse\_id: You must configure Discourse ID credentials ('discourse\_id\_client\_id' and 'discourse\_id\_client\_secret')…

---

## [LDAP badge?](https://meta.discourse.org/t/ldap-badge/382116)

<div class="topic-metadata">

**Author:** [@strk](https://meta.discourse.org/u/strk)\
**Replies:** 3\
**Last updated:** [September 12, 2025, 11:40am UTC](https://meta.discourse.org/t/ldap-badge/382116 "2025-09-12T11:40:15Z")

</div>

Hello, is it possible to assign a badge to those whose username matches the LDAP username and were authenticated via LDAP ? We currently allow rigistering local accounts too so someone could register someone else’s LDAP …

---

## [Syncing email notification and summary preferences from SSO provider](https://meta.discourse.org/t/syncing-email-notification-and-summary-preferences-from-sso-provider/358766)

<div class="topic-metadata">

**Author:** [@KurtTrowbridge](https://meta.discourse.org/u/KurtTrowbridge)\
**Replies:** 1\
**Last updated:** [September 17, 2025, 12:37pm UTC](https://meta.discourse.org/t/syncing-email-notification-and-summary-preferences-from-sso-provider/358766 "2025-09-17T12:37:31Z")

</div>

I’m working on a Discourse integration with a Drupal website (using the Discourse SSO Drupal module) and have been able to answer most of my questions with existing documentation. However, I’m stumped on this one: If po…

---

## [Overriding avatars with OIDC](https://meta.discourse.org/t/overriding-avatars-with-oidc/304291)

<div class="topic-metadata">

**Author:** [@Wilson\_Ho](https://meta.discourse.org/u/Wilson_Ho)\
**Replies:** 3\
**Last updated:** [September 10, 2025, 9:16am UTC](https://meta.discourse.org/t/overriding-avatars-with-oidc/304291 "2025-09-10T09:16:57Z")

</div>

Is there any way this plugin could overrides avatar, just like DiscourseConnect does?

---

## [Avatar is synching only on creation](https://meta.discourse.org/t/avatar-is-synching-only-on-creation/304286)

<div class="topic-metadata">

**Author:** [@weber-s](https://meta.discourse.org/u/weber-s)\
**Replies:** 4\
**Last updated:** [September 2, 2025, 4:50pm UTC](https://meta.discourse.org/t/avatar-is-synching-only-on-creation/304286 "2025-09-02T16:50:04Z")

</div>

Hello there! I’m using this plugin to sync user from a django site, but the avatar is sync only on creation. If user change it in django, it is not sync in discourse. In fact, in Discourse managed\_authenticator.rb, the…

---

## [Changing SSO for new IDP](https://meta.discourse.org/t/changing-sso-for-new-idp/379959)

<div class="topic-metadata">

**Author:** [@BlueTigger87](https://meta.discourse.org/u/BlueTigger87)\
**Replies:** 0\
**Last updated:** [August 22, 2025, 8:21pm UTC](https://meta.discourse.org/t/changing-sso-for-new-idp/379959 "2025-08-22T20:21:05Z")

</div>

We are transitioning our Single Sign-On (SSO) system due to a change in our database. We need to find the best way to link users to their existing forum accounts. Is it possible to backfill user IDs into the system so th…

---

## [Sometimes toast the message "you were logged out"](https://meta.discourse.org/t/sometimes-toast-the-message-you-were-logged-out/372722)

<div class="topic-metadata">

**Author:** [@pkward](https://meta.discourse.org/u/pkward)\
**Replies:** 9\
**Last updated:** [July 7, 2025, 8:36am UTC](https://meta.discourse.org/t/sometimes-toast-the-message-you-were-logged-out/372722 "2025-07-07T08:36:47Z")

</div>

We have a problem with keeping user logged in. We connect discourse to our app with sso. Login Success and redirect to discourse click some board popup “you were logged out” our guess are below \_forum\_session value i…

[Next page](https://meta.discourse.org/c/support/sso/24.md?page=1)
