Z
ZITADEL
Z
ZITADEL
Getting invalid_client, client authentication failed.
Original message was deleted
ZITADEL
Join
ZITADEL - Identity infrastructure, simplified for you.
4,316
Members
View on Discord
F
FFO
•
7/3/24, 9:00 AM
Hm can you share the URL when you see that error
F
FFO
•
7/3/24, 9:07 AM
and how does the error look like
, can you send a screenshot
?
F
FFO
•
7/3/24, 9:09 AM
Ok so something between zitadel and the idp did go wrong
.
What IDP are you using
?
F
FFO
•
7/3/24, 9:11 AM
Hm zitadel should log something if that happens
F
FFO
•
7/3/24, 9:12 AM
We have seen problems though with onelogin all the time
F
FFO
•
7/3/24, 9:12 AM
What auth method do you use
?
F
FFO
•
7/3/24, 9:25 AM
Thats weird
, what log level do you run
?
F
FFO
•
7/3/24, 9:31 AM
To proceed here can you share your config and the logs per DM
?
F
FFO
•
7/3/24, 7:48 PM
Ok
, you should see the callback to zitadel
, what does that call contain
?
F
FFO
•
7/3/24, 8:10 PM
To me that sounds like onelogin has an issue with the prompt value
F
FFO
•
7/3/24, 8:10 PM
I think the simply fail when using that
F
FFO
•
7/4/24, 8:12 AM
Weird
, let me bump this internally and see if somebody has an idea
F
FFO
•
7/4/24, 10:38 AM
Just to have a summary
.
You have a react app attached to zitadel and zitadel tries to use onelogin as an upstream idp
, right
?
F
FFO
•
7/4/24, 11:59 AM
ok thanks
F
FFO
•
7/10/24, 11:03 AM
ATM the team is a little strained since its vacation time
I think the only
"good
" working approach will be to create an IDP template for onelogin since they do weird things
F
fabienne
•
8/7/24, 3:22 PM
An IDP template is a predefined idp provider
, so that you can choose onelogin as provider when creating a new idp instead of a generic one
.
F
fabienne
•
8/7/24, 3:22 PM
You could contribute that in the zitadel repository if you would like to push that forward
F
fabienne
•
8/7/24, 3:23 PM
So basically to have an option one login here
:
F
fabienne
•
11/20/24, 10:38 AM
Hi
@Sinan does it really need to be pkce
? did you read that somewhere
? Looking at the docs here
, it tells if code
_challende
_method is set to none then it will do pkce
:
https://developers.onelogin.com/openid-connect/api/authorization-code
would it be possible to do basic
?
OneLogin Developers
OpenID Connect Auth Code Flow pt. 1 - OneLogin API
Q
Quintonn
@fabienne @FFO hi, looking at this again. If we were to try add a template, do ...
F
fabienne
•
11/20/24, 10:39 AM
We do not yet have concrete docs about how to add another provider template
. The easiest way is probably
, to have a look at the apis from another provider like google
, and search in the repository for this
, take that as an example
.
F
fabienne
•
11/20/24, 11:36 AM
great thanks for the info