Prompt
sso login loop after redirect
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
An SSO login loop after redirect usually means the app thinks you’re still unauthenticated when it comes back from the IdP. Common causes are:
Most common causes
-
Session/cookie not being stored or sent
- Cookie domain/path mismatch
SameSiteissue, especially with cross-site redirectsSecuremissing on HTTPS cookies- Third-party cookie blocking
-
Redirect URI mismatch
- The callback URL configured in the IdP doesn’t exactly match the one used by the app
- Trailing slash, http vs https, port, or subdomain differences
-
State/nonce/session lost during the auth flow
- The app stores auth state in a session cookie, but that cookie isn’t available on the callback request
-
Token exchange or callback handling failing
- Authorization code received, but backend fails to exchange it for tokens
- User is redirected back to login instead of being logged in
-
Frontend/backend domain mismatch
- SPA on one domain, API on another, cookies not shared correctly
- CORS/credentials misconfiguration
-
Reverse proxy / load balancer issues
- App sees requests as HTTP instead of HTTPS
- Sticky sessions missing if auth state is stored in-memory
Things to check
- Browser dev tools → Network:
- Is the callback request returning
302back to login? - Is the session cookie set on the callback response?
- Is the callback request returning
- Browser dev tools → Application/Storage:
- Is the auth/session cookie present after login?
- Inspect cookie attributes:
DomainPathSameSiteSecureHttpOnly
- Confirm the IdP redirect URI exactly matches app config.
- Check server logs for:
- “invalid state”
- “missing session”
- “token exchange failed”
- “unauthorized”
If this is a browser-based app
Try setting cookies like:
SameSite=NoneSecure=true- correct
Domainfor the site
If you’re using a proxy:
- Ensure forwarded headers are handled correctly:
X-Forwarded-ProtoX-Forwarded-Host
Quick diagnostic questions
If you want, I can help narrow it down if you tell me:
- Which SSO provider? (Okta, Azure AD, Auth0, Keycloak, etc.)
- App type? (SPA, server-rendered web app, mobile)
- What happens after redirect? Any error, or just back to login?
- Are you using cookies/session or JWT?
- Any relevant callback URL / cookie settings / proxy setup?
If you share a small snippet of your config or a browser/network trace, I can help pinpoint the likely cause.