# \#openid-connect

**URL:** https://meta.discourse.org/tag/openid-connect/243.md

[Latest](https://meta.discourse.org/latest.md) · [Categories](https://meta.discourse.org/categories.md) · [Tags](https://meta.discourse.org/tags.md)

---

## [OIDC login fails with ID-token-only responses after OAuth2 2.x upgrade](https://meta.discourse.org/t/oidc-login-fails-with-id-token-only-responses-after-oauth2-2-x-upgrade/412518)

<div class="topic-metadata">

**Author:** [@levarm](https://meta.discourse.org/u/levarm)\
**Replies:** 2\
**Last updated:** [September 16, 2026, 11:08am UTC](https://meta.discourse.org/t/oidc-login-fails-with-id-token-only-responses-after-oauth2-2-x-upgrade/412518 "2026-09-16T11:08:30Z")

</div>

After updating our self-hosted Discourse environments on 11 September 2026, OIDC login started failing with: (oidc) Authentication failure! jwt\_decode\_failed: JWT::DecodeError, Nil JSON web token Our older dev environm…

---

## [Allowing multiple OIDC sources](https://meta.discourse.org/t/allowing-multiple-oidc-sources/304290)

<div class="topic-metadata">

**Author:** [@dalu74](https://meta.discourse.org/u/dalu74)\
**Replies:** 6\
**Last updated:** [August 19, 2026, 11:56am UTC](https://meta.discourse.org/t/allowing-multiple-oidc-sources/304290 "2026-08-19T11:56:40Z")

</div>

This is great, much better than the oauth2 plugin, which didn’t work. But this one does (with Keycloak). However multiple oidc sources would be a very welcome feature.

---

## [Connect User logins from my Wix site for my Discourse forum](https://meta.discourse.org/t/connect-user-logins-from-my-wix-site-for-my-discourse-forum/407636)

<div class="topic-metadata">

**Author:** [@Gid](https://meta.discourse.org/u/Gid)\
**Replies:** 12\
**Last updated:** [July 16, 2026, 4:19am UTC](https://meta.discourse.org/t/connect-user-logins-from-my-wix-site-for-my-discourse-forum/407636 "2026-07-16T04:19:58Z")

</div>

I have a Wix website on a paid plan (Core). The site’s members (people who’ve just signed up on my site) are well integrated into it, with their details & connections are stored on Wix’s powerful CMSs. So my Wix site is…

---

## [Discourse OpenID Connect (OIDC)](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632)

<div class="topic-metadata">

**Author:** [@Discourse](https://meta.discourse.org/u/Discourse)\
**Replies:** 46\
**Last updated:** [May 27, 2026, 4:34pm UTC](https://meta.discourse.org/t/discourse-openid-connect-oidc/103632 "2026-05-27T16:34:25Z")

</div>

:discourse2: Summary Discourse OpenID Connect allows an OpenID Connect provider to be used as an authentication provider for Discourse. :open\_book: Install Guide This plugin is bundled with Discourse core.…

---

## [OpenID Connect group can kick users out of all unsynced groups](https://meta.discourse.org/t/openid-connect-group-can-kick-users-out-of-all-unsynced-groups/402416)

<div class="topic-metadata">

**Author:** [@Steradiant](https://meta.discourse.org/u/Steradiant)\
**Replies:** 6\
**Last updated:** [May 12, 2026, 7:52pm UTC](https://meta.discourse.org/t/openid-connect-group-can-kick-users-out-of-all-unsynced-groups/402416 "2026-05-12T19:52:03Z")

</div>

Under certain conditions, the OpenID Connect group sync kicks users out of all Discourse groups without a synced oidc group. The logs and overall situation indicate that this is triggered when a user looses a single (un…

---

## [OIDC users not associating with existing Discourse users](https://meta.discourse.org/t/oidc-users-not-associating-with-existing-discourse-users/383894)

<div class="topic-metadata">

**Author:** [@WurstLander](https://meta.discourse.org/u/WurstLander)\
**Replies:** 4\
**Last updated:** [May 4, 2026, 5:06am UTC](https://meta.discourse.org/t/oidc-users-not-associating-with-existing-discourse-users/383894 "2026-05-04T05:06:35Z")

</div>

Hi! I’m trying to set up Discourse with the Discourse OpenID Connect plugin and Keycloak. I’ve managed to make it work, and was able to not only login to my Discourse instance using my Keycloak credentials, but also ass…

---

## [Allowed email domains](https://meta.discourse.org/t/allowed-email-domains/401552)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 0\
**Last updated:** [April 26, 2026, 11:16am UTC](https://meta.discourse.org/t/allowed-email-domains/401552 "2026-04-26T11:16:05Z")

</div>

My reading of the docs is that allowed email domains is checked against the email returned by OIDC during account creation. Can anyone confirm?

---

## [How is it possible to connect Discourse with two OIDC providers?](https://meta.discourse.org/t/how-is-it-possible-to-connect-discourse-with-two-oidc-providers/304280)

<div class="topic-metadata">

**Author:** [@sebix1](https://meta.discourse.org/u/sebix1)\
**Replies:** 3\
**Last updated:** [April 25, 2026, 8:06am UTC](https://meta.discourse.org/t/how-is-it-possible-to-connect-discourse-with-two-oidc-providers/304280 "2026-04-25T08:06:47Z")

</div>

I managed to connect GitLab and Microsoft (Azure) with this plugin. btw: for the Azure AD service, make sure to use the “Application Client ID” as client id, not the secret ID or value). How is it possible to connect Di…

---

## [When OpenID Connect overrides email](https://meta.discourse.org/t/when-openid-connect-overrides-email/401037)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 0\
**Last updated:** [April 20, 2026, 10:25am UTC](https://meta.discourse.org/t/when-openid-connect-overrides-email/401037 "2026-04-20T10:25:29Z")

</div>

On a self-hosted site using OpenID Connect, is there a supported Rails console method to mark an existing alternate email in user\_emails as confirmed without changing the account’s primary email? Goal: avoid duplicate a…

---

## [OIDC Error for OpenAI Discourse forum](https://meta.discourse.org/t/oidc-error-for-openai-discourse-forum/400392)

<div class="topic-metadata">

**Author:** [@EricGT](https://meta.discourse.org/u/EricGT)\
**Replies:** 7\
**Last updated:** [April 11, 2026, 1:15pm UTC](https://meta.discourse.org/t/oidc-error-for-openai-discourse-forum/400392 "2026-04-11T13:15:48Z")

</div>

For OpenAI Discourse forum trying to login in and receive Sorry, there was an error while trying to authorize your account with oidc. Please try again. I have been using OpenAI Discourse almost daily for the last …

---

## [Allow to disable email verification when using oidc](https://meta.discourse.org/t/allow-to-disable-email-verification-when-using-oidc/398963)

<div class="topic-metadata">

**Author:** [@Steradiant](https://meta.discourse.org/u/Steradiant)\
**Replies:** 0\
**Last updated:** [March 21, 2026, 12:36pm UTC](https://meta.discourse.org/t/allow-to-disable-email-verification-when-using-oidc/398963 "2026-03-21T12:36:50Z")

</div>

For the oauth2 authentication, there is a setting “OAuth2 email verified” which allows to disable email verification. However, for oidc, no analogous option exists. Can this be added?

---

## [I’m seeing OIDC failures in Discourse logs: \`CSRFTokenVerifier::InvalidCSRFToken\` on \`/auth/oidc\` (POST)](https://meta.discourse.org/t/i-m-seeing-oidc-failures-in-discourse-logs-csrftokenverifier-invalidcsrftoken-on-auth-oidc-post/395752)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 0\
**Last updated:** [February 11, 2026, 7:26am UTC](https://meta.discourse.org/t/i-m-seeing-oidc-failures-in-discourse-logs-csrftokenverifier-invalidcsrftoken-on-auth-oidc-post/395752 "2026-02-11T07:26:07Z")

</div>

Hi all, I’m running Discourse 2026.2.0-latest (26f3e2aa87) (Docker install, default nginx template, no Cloudflare). I have OpenID Connect enabled (Microsoft Entra / Azure AD). When a user tries to sign up / log in via…

---

## [OIDC csrf\_detected can mask user cancel / consent rejection - docs could clarify log inspection](https://meta.discourse.org/t/oidc-csrf-detected-can-mask-user-cancel-consent-rejection-docs-could-clarify-log-inspection/395021)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 1\
**Last updated:** [February 5, 2026, 9:16pm UTC](https://meta.discourse.org/t/oidc-csrf-detected-can-mask-user-cancel-consent-rejection-docs-could-clarify-log-inspection/395021 "2026-02-05T21:16:57Z")

</div>

Continuing the discussion from OIDC login via Discourse iOS app occasionally fails with csrf\_detected on callback: Hi all, This is a follow-up observation linked to my earlier thread about OIDC login failures initiated…

---

## [OIDC login via Discourse iOS app occasionally fails with csrf\_detected on callback](https://meta.discourse.org/t/oidc-login-via-discourse-ios-app-occasionally-fails-with-csrf-detected-on-callback/394838)

<div class="topic-metadata">

**Author:** [@Ethsim2](https://meta.discourse.org/u/Ethsim2)\
**Replies:** 4\
**Last updated:** [February 2, 2026, 8:46pm UTC](https://meta.discourse.org/t/oidc-login-via-discourse-ios-app-occasionally-fails-with-csrf-detected-on-callback/394838 "2026-02-02T20:46:42Z")

</div>

Hi, I’m running Discourse ( 2026.2.0-latest (f7cec86997))with OpenID Connect (Azure / Entra ID as IdP). I’ve noticed an occasional login failure that only seems to occur when users attempt to sign in via the Discourse …

---

## [Invite Only with OpenID only does not work](https://meta.discourse.org/t/invite-only-with-openid-only-does-not-work/386172)

<div class="topic-metadata">

**Author:** [@DevTeVe](https://meta.discourse.org/u/DevTeVe)\
**Replies:** 3\
**Last updated:** [January 20, 2026, 10:40pm UTC](https://meta.discourse.org/t/invite-only-with-openid-only-does-not-work/386172 "2026-01-20T22:40:15Z")

</div>

Currently we are doing a test-pilot of our forum and we wanted to limit the amount of people that can join. We’ve configured openid and wanted to enable All new users must be explicitly invited by trusted users or staff…

---

## [Invite only forum with Google, OIDC or Oauth2 login](https://meta.discourse.org/t/invite-only-forum-with-google-oidc-or-oauth2-login/387802)

<div class="topic-metadata">

**Author:** [@phil22](https://meta.discourse.org/u/phil22)\
**Replies:** 2\
**Last updated:** [November 12, 2025, 10:43am UTC](https://meta.discourse.org/t/invite-only-forum-with-google-oidc-or-oauth2-login/387802 "2025-11-12T10:43:57Z")

</div>

Hello, I have a self hosted discourse instance. I have set up the OIDC connect plugin to sign in users with their google account. Using the settings in the google cloud console I’m able to limit this to users within my …

---

## [Overriding avatars with OIDC](https://meta.discourse.org/t/overriding-avatars-with-oidc/304291)

<div class="topic-metadata">

**Author:** [@Wilson\_Ho](https://meta.discourse.org/u/Wilson_Ho)\
**Replies:** 3\
**Last updated:** [September 10, 2025, 9:16am UTC](https://meta.discourse.org/t/overriding-avatars-with-oidc/304291 "2025-09-10T09:16:57Z")

</div>

Is there any way this plugin could overrides avatar, just like DiscourseConnect does?

---

## [OIDC Error](https://meta.discourse.org/t/oidc-error/381829)

<div class="topic-metadata">

**Author:** [@screwballs](https://meta.discourse.org/u/screwballs)\
**Replies:** 2\
**Last updated:** [September 8, 2025, 1:55pm UTC](https://meta.discourse.org/t/oidc-error/381829 "2025-09-08T13:55:39Z")

</div>

I’m using using the discourse openid connect plugin, and all of a sudden users are getting this error. Sorry, there was an error while trying to authorize your acocunt with OIDC. Please try again. Got a ticket open w…

---

## [Avatar is synching only on creation](https://meta.discourse.org/t/avatar-is-synching-only-on-creation/304286)

<div class="topic-metadata">

**Author:** [@weber-s](https://meta.discourse.org/u/weber-s)\
**Replies:** 4\
**Last updated:** [September 2, 2025, 4:50pm UTC](https://meta.discourse.org/t/avatar-is-synching-only-on-creation/304286 "2025-09-02T16:50:04Z")

</div>

Hello there! I’m using this plugin to sync user from a django site, but the avatar is sync only on creation. If user change it in django, it is not sync in discourse. In fact, in Discourse managed\_authenticator.rb, the…

---

## [Triggering automatic authentication via OIDC when linking to private topics?](https://meta.discourse.org/t/triggering-automatic-authentication-via-oidc-when-linking-to-private-topics/364411)

<div class="topic-metadata">

**Author:** [@tyler.lamparter](https://meta.discourse.org/u/tyler.lamparter)\
**Replies:** 1\
**Last updated:** [May 3, 2025, 11:08pm UTC](https://meta.discourse.org/t/triggering-automatic-authentication-via-oidc-when-linking-to-private-topics/364411 "2025-05-03T23:08:06Z")

</div>

I’m trying to get the functionality specified in this thread, but with OIDC. This thread seems to only be related to DiscourseConnect, and when I attempt the same thing for our OIDC config, it doesn’t work. Does anyone h…

---

## [Disable activation email for OIDC users?](https://meta.discourse.org/t/disable-activation-email-for-oidc-users/324537)

<div class="topic-metadata">

**Author:** [@steinhh](https://meta.discourse.org/u/steinhh)\
**Replies:** 1\
**Last updated:** [April 15, 2025, 6:07pm UTC](https://meta.discourse.org/t/disable-activation-email-for-oidc-users/324537 "2025-04-15T18:07:57Z")

</div>

Hi, is there a way to disable activation emails for users authenticating with OIDC? We have openid connect overrides email set to yes anyways(\*), and some people are notoriously unable to search their spam folders… Give…

---

## [Non-commercial support for the 1.x series oauth gem will end by April, 2025, what then?](https://meta.discourse.org/t/non-commercial-support-for-the-1-x-series-oauth-gem-will-end-by-april-2025-what-then/355336)

<div class="topic-metadata">

**Author:** [@steinhh](https://meta.discourse.org/u/steinhh)\
**Replies:** 0\
**Last updated:** [March 2, 2025, 6:28pm UTC](https://meta.discourse.org/t/non-commercial-support-for-the-1-x-series-oauth-gem-will-end-by-april-2025-what-then/355336 "2025-03-02T18:28:00Z")

</div>

Hi! Me again, being forced to install on RHEL9 this time, and I notice that the oauth gem says: Non-commercial support for the 1.x series will end by April, 2025 I’m uncomfortable with running non-supported stuff, an…

---

## [OpenID Connect and sub mismatch](https://meta.discourse.org/t/openid-connect-and-sub-mismatch/342029)

<div class="topic-metadata">

**Author:** [@Jagster](https://meta.discourse.org/u/Jagster)\
**Replies:** 2\
**Last updated:** [February 25, 2025, 6:14am UTC](https://meta.discourse.org/t/openid-connect-and-sub-mismatch/342029 "2025-02-25T06:14:53Z")

</div>

A user can log in to provider (WordPress if than plays any roll) and when that user returns to Discourse, it waits a bit and tells it didn’t happen. I see this in logs: openid\_connect\_sub\_mismatch: OmniAuth::Strategies:…

---

## [OpenID Connect and JWT Key for WAF](https://meta.discourse.org/t/openid-connect-and-jwt-key-for-waf/348301)

<div class="topic-metadata">

**Author:** [@sandra.mccollum](https://meta.discourse.org/u/sandra.mccollum)\
**Replies:** 0\
**Last updated:** [January 22, 2025, 2:00am UTC](https://meta.discourse.org/t/openid-connect-and-jwt-key-for-waf/348301 "2025-01-22T02:00:21Z")

</div>

I am considering using Discourse OpenID Connect. I want to integrate with a WAF, which wants the JWT Key, can anyone tell me where to find the key? I have created the client in the Google Cloud Console, just not sure w…

---

## [OIDC: Authorization timed out](https://meta.discourse.org/t/oidc-authorization-timed-out/165631)

<div class="topic-metadata">

**Author:** [@Martin\_Delille](https://meta.discourse.org/u/Martin_Delille)\
**Replies:** 2\
**Last updated:** [January 3, 2025, 1:00pm UTC](https://meta.discourse.org/t/oidc-authorization-timed-out/165631 "2025-01-03T13:00:20Z")

</div>

When I connect using the plugin I have the following error: Authorization timed out, or you have switched browsers. Please try again. but if I click on the forum logo, I’m correctly logged in. When looking at the log I …

---

## [OAUTH flow to Integrate the discourse community account with the third party CRM tool where it can create tickets of community](https://meta.discourse.org/t/oauth-flow-to-integrate-the-discourse-community-account-with-the-third-party-crm-tool-where-it-can-create-tickets-of-community/343092)

<div class="topic-metadata">

**Author:** [@kekafel](https://meta.discourse.org/u/kekafel)\
**Replies:** 2\
**Last updated:** [December 18, 2024, 6:45am UTC](https://meta.discourse.org/t/oauth-flow-to-integrate-the-discourse-community-account-with-the-third-party-crm-tool-where-it-can-create-tickets-of-community/343092 "2024-12-18T06:45:01Z")

</div>

I want to integrate discourse Account with the CRM tool that I have where what I want is as follows :- User can add their Discourse community account in my tool using his discourse loginId and password . Discourse sh…

---

## [Account already in discourse](https://meta.discourse.org/t/account-already-in-discourse/318378)

<div class="topic-metadata">

**Author:** [@Jaskaran](https://meta.discourse.org/u/Jaskaran)\
**Replies:** 1\
**Last updated:** [July 25, 2024, 3:52pm UTC](https://meta.discourse.org/t/account-already-in-discourse/318378 "2024-07-25T15:52:01Z")

</div>

hi everyone I am in big trouble because we migate user data into site after this i connect with OpenId Plugin . now after verification from the open ID provider it is coming back to discourse and asking to create userna…

---

## [Login with openID](https://meta.discourse.org/t/login-with-openid/313497)

<div class="topic-metadata">

**Author:** [@Jaskaran](https://meta.discourse.org/u/Jaskaran)\
**Replies:** 0\
**Last updated:** [June 25, 2024, 6:50am UTC](https://meta.discourse.org/t/login-with-openid/313497 "2024-06-25T06:50:11Z")

</div>

Hi everyone , I want to ask regarding this page , When user login from openID connect first time it is asking for username . Is this username store in discourse side . I want to store that also with service provider .…

---

## [Regarding OIDC pluging Get USerInfo REsponse](https://meta.discourse.org/t/regarding-oidc-pluging-get-userinfo-response/313018)

<div class="topic-metadata">

**Author:** [@Jaskaran](https://meta.discourse.org/u/Jaskaran)\
**Replies:** 0\
**Last updated:** [June 21, 2024, 7:07am UTC](https://meta.discourse.org/t/regarding-oidc-pluging-get-userinfo-response/313018 "2024-06-21T07:07:13Z")

</div>

I want to ask about the discourse openID plugin for userReponse get API is it required to have application/json type. because currently OIDC provider returns as application/jwt. UserInfo · Docs · Connect2id and the us…

---

## [Add configurable option for choosing between JWT and UserInfo](https://meta.discourse.org/t/add-configurable-option-for-choosing-between-jwt-and-userinfo/312951)

<div class="topic-metadata">

**Author:** [@klin938](https://meta.discourse.org/u/klin938)\
**Replies:** 0\
**Last updated:** [June 20, 2024, 9:28pm UTC](https://meta.discourse.org/t/add-configurable-option-for-choosing-between-jwt-and-userinfo/312951 "2024-06-20T21:28:23Z")

</div>

Hi guys, I am having an issue when setting up oidc with our Azure AD backend. I want to use preferred\_username as the default username since this is only field which is unique (email and name are recycled and reusable) …

[Next page](https://meta.discourse.org/tag/openid-connect/243.md?match_all_tags=true&page=1&tags%5B%5D=openid-connect)
