Prompt
How do I find out why an enterprise login is stuck in redirect loop?
Latest observation
A redirect loop usually means the app and the Identity Provider (IdP) are disagreeing about session state, callback URLs, cookies, or token validation. To find the cause, troubleshoot in this order:
1) Capture the exact redirect chain
Use browser dev tools or curl to see where it bounces.
In browser
- Open DevTools → Network
- Check Preserve log
- Reproduce the login
- Look for repeated
302/303responses - Note:
- the start URL
- each Location header
- where the loop repeats
With curl
curl -vkL --max-redirs 20 https://your-app.example.com/login
If it loops, inspect each Location: and response code.
2) Identify whether the loop is in the app or the IdP
A common pattern:
- App redirects to IdP
- IdP redirects back to app callback
- App says “not authenticated” and redirects again
That usually means the app is not accepting the IdP response.
Check:
- Is the callback route reachable?
- Does the app set a session cookie after callback?
- Does the browser send that cookie back?
3) Check cookies and SameSite behavior
This is one of the most common causes.
Look for:
- Session cookie not being set
- Cookie set on a different domain/subdomain
SameSite=Lax/Strictblocking the cookie during cross-site loginSecurecookie being rejected on HTTP- Cookie path/domain mismatch
Things to verify:
- If login crosses domains, cookie often needs:
SameSite=NoneSecure
- If using
localhost, some browsers handle cookies differently.
4) Verify redirect/callback URLs match exactly
Misconfigured callback URLs often cause loops.
Check:
- Registered redirect URI in IdP
- App’s configured redirect URI
- Exact match including:
- scheme
httpvshttps - host
- port
- path
- trailing slash
- uppercase/lowercase if relevant
- scheme
Even small mismatches can cause the app to reject the response and restart login.
5) Inspect state/nonce/PKCE handling
If the app uses OIDC/OAuth:
statemismatchnoncemismatch- PKCE verifier missing
- expired auth request
Causes:
- session cookie lost before callback
- load balancer sending callback to different instance without shared session store
- browser privacy settings blocking storage
6) Check SSO session vs app session
Sometimes the IdP session is fine, but the app session is not created or not persisted.
Verify:
- The app creates a local session after successful IdP response
- Session store works (Redis, DB, in-memory)
- Multiple app instances share session state
- The user isn’t immediately redirected to login because authorization middleware thinks they’re anonymous
7) Look at server logs on both sides
App logs
Search for:
- authentication callback received
- invalid state
- cookie/session errors
- token validation errors
- unauthorized/forbidden immediately after login
IdP logs
Search for:
- invalid redirect URI
- consent errors
- MFA/challenge issues
- token exchange failures
- session not established
If possible, correlate by request ID / trace ID.
8) Check for proxy/load balancer issues
If there’s a reverse proxy or ingress:
- Is
X-Forwarded-Protocorrect? - Does the app think the request is HTTP when it is actually HTTPS?
- Is TLS terminated upstream?
- Are headers stripped or rewritten?
Common symptom:
- App sets a cookie for HTTP or wrong domain
- Callback arrives on a different host than expected
9) Disable extensions and privacy blockers
Browser extensions can break login:
- ad blockers
- privacy tools
- third-party cookie blocking
- tracking protection
Test in:
- incognito/private window
- another browser
- a clean profile
10) Test a minimal repro
Try:
- direct IdP login page
- a simple test app using the same IdP config
- a different network/device
If the simple app works, the issue is likely in your app’s session/cookie/configuration.
Fast checklist
Most redirect loops are caused by one of these:
- wrong redirect URI
- cookie blocked by
SameSite/Secure - session not persisted across instances
- app behind proxy misreading scheme/host
- invalid
state/nonce/PKCE - callback route not handling the auth response
What to collect
To diagnose quickly, gather:
- full redirect chain
- app and IdP logs
- cookie details from browser dev tools
- exact callback URL configured in both places
- whether the app is behind a proxy or load balancer
- whether the problem happens in one browser only
If you want, I can help you troubleshoot a specific redirect trace or log snippet.