[GH-ISSUE #5723] OIDC user on logout from dashboard does not log user out with internal IdP disabled #11686

Closed
opened 2026-08-05 01:30:28 -04:00 by saavagebueno · 7 comments
Owner

Originally created by @klinkeye on GitHub (Mar 28, 2026).
Original GitHub issue: https://github.com/netbirdio/netbird/issues/5723

Describe the problem

User is immediately logged back in to Netbird when logging out from the Dashboard, if internal IdP is disabled. In my case Authentik is the IdP.

To Reproduce

Steps to reproduce the behavior:

  1. Ensure internal IdP is disabled
  2. Log into Netbird via IdP
  3. Click on user top right and select log out
  4. User is logged out, but then redirected to IdP and logged back in due to IdP session still valid

Expected behavior

User should be logged out of Netbird, and remain logged out.

Are you using NetBird Cloud?

Self-hosted

NetBird version

Management v0.67.1
Dashboard v2.36.0

Is any other VPN software installed?

No

Debug output

Peers detail:
flex-per-fw01.netbird.ftl.anon-1V9Bj.domain:
NetBird IP: 100.125.71.121
Public key: Xpxx7v/grDuTKJ/XQZsOy7LkJQV2lsNCdPQSE0hlzyc=
Status: Connected
-- detail --
Connection type: P2P
ICE candidate (Local/Remote): srflx/host
ICE candidate endpoints (Local/Remote): 198.51.100.0:51820/198.51.100.1:30018
Relay server address: rels://netbird.ftl.anon-1V9Bj.domain:443
Last connection update: 20 minutes, 16 seconds ago
Last WireGuard handshake: 1 minute, 29 seconds ago
Transfer status (received/sent) 132.4 KiB/131.4 KiB
Quantum resistance: false
Networks: -
Latency: 59.5544ms

desktop-ssqsibm.netbird.ftl.anon-1V9Bj.domain:
NetBird IP: 100.125.72.59
Public key: dgiqGLPGw1pNGfNcE4ArFMNNnyrdUtN65mnPbj/UmDY=
Status: Connecting
-- detail --
Connection type: -
ICE candidate (Local/Remote): -/-
ICE candidate endpoints (Local/Remote): -/-
Relay server address:
Last connection update: 23 minutes, 46 seconds ago
Last WireGuard handshake: -
Transfer status (received/sent) 0 B/0 B
Quantum resistance: false
Networks: -
Latency: 0s

Events:
[INFO] SYSTEM (777999db-d0da-4a2c-b1a8-0cde2cb716f4)
Message: Network map updated
Time: 1 hour, 34 minutes ago
[INFO] SYSTEM (11838915-9e83-4ed6-8e1e-9f38c13f9271)
Message: Network map updated
Time: 1 hour, 30 minutes ago
[INFO] SYSTEM (aae7ddec-8749-4abf-8019-645716d879ac)
Message: Network map updated
Time: 1 hour, 28 minutes ago
[INFO] SYSTEM (b2d44ce6-55a1-4dba-9cd8-86327a8271ea)
Message: Network map updated
Time: 1 hour, 7 minutes ago
[INFO] SYSTEM (aecf7265-695f-4d77-891a-6e4fded9a6ad)
Message: Network map updated
Time: 1 hour, 6 minutes ago
[INFO] SYSTEM (03c65c1a-9b5c-42cd-b09d-6dd64bf4f632)
Message: Network map updated
Time: 41 minutes, 19 seconds ago
[INFO] SYSTEM (0d562360-43bd-484c-95f8-3f8cd393e6bf)
Message: Network map updated
Time: 23 minutes, 46 seconds ago
[INFO] SYSTEM (aae0d96d-1de1-44f8-8ccd-8cc66e88b83a)
Message: Network map updated
Time: 23 minutes, 34 seconds ago
[INFO] SYSTEM (17ed1f3e-3e12-4117-a1a9-894ee874d543)
Message: Network map updated
Time: 21 minutes, 1 seconds ago
[INFO] SYSTEM (a164c301-a996-4b46-9bed-c2ede804b3d8)
Message: Network map updated
Time: 20 minutes, 15 seconds ago
OS: windows/amd64
Daemon version: 0.67.1
CLI version: 0.67.1
Profile: FTL-test1
Management: Connected to https://netbird.ftl.anon-1V9Bj.domain:443
Signal: Connected to https://netbird.ftl.anon-1V9Bj.domain:443
Relays:
[stun:netbird.ftl.anon-1V9Bj.domain:3478] is Available
[rels://netbird.ftl.anon-1V9Bj.domain:443] is Available
Nameservers:
FQDN: desktop-ssqsibm-116-4.netbird.ftl.anon-1V9Bj.domain
NetBird IP: 100.125.116.4/16
Interface type: Userspace
Quantum resistance: false
Lazy connection: false
SSH Server: Disabled
Networks: -
Peers count: 1/2 Connected

Create and upload a debug bundle, and share the returned file key:

netbird debug for 1m -AS -U

Uploaded files are automatically deleted after 30 days.

Alternatively, create the file only and attach it here manually:

netbird debug for 1m -AS

Screenshots

If applicable, add screenshots to help explain your problem.

Additional context

Add any other context about the problem here.

Have you tried these troubleshooting steps?

  • Reviewed client troubleshooting (if applicable)
  • Checked for newer NetBird versions
  • Searched for similar issues on GitHub (including closed ones)
  • Restarted the NetBird client
  • Disabled other VPN software
  • Checked firewall settings
Originally created by @klinkeye on GitHub (Mar 28, 2026). Original GitHub issue: https://github.com/netbirdio/netbird/issues/5723 **Describe the problem** User is immediately logged back in to Netbird when logging out from the Dashboard, if internal IdP is disabled. In my case Authentik is the IdP. **To Reproduce** Steps to reproduce the behavior: 1. Ensure internal IdP is disabled 2. Log into Netbird via IdP 3. Click on user top right and select log out 4. User is logged out, but then redirected to IdP and logged back in due to IdP session still valid **Expected behavior** User should be logged out of Netbird, and remain logged out. **Are you using NetBird Cloud?** Self-hosted **NetBird version** `Management v0.67.1` `Dashboard v2.36.0` **Is any other VPN software installed?** No **Debug output** Peers detail: flex-per-fw01.netbird.ftl.anon-1V9Bj.domain: NetBird IP: 100.125.71.121 Public key: Xpxx7v/grDuTKJ/XQZsOy7LkJQV2lsNCdPQSE0hlzyc= Status: Connected -- detail -- Connection type: P2P ICE candidate (Local/Remote): srflx/host ICE candidate endpoints (Local/Remote): 198.51.100.0:51820/198.51.100.1:30018 Relay server address: rels://netbird.ftl.anon-1V9Bj.domain:443 Last connection update: 20 minutes, 16 seconds ago Last WireGuard handshake: 1 minute, 29 seconds ago Transfer status (received/sent) 132.4 KiB/131.4 KiB Quantum resistance: false Networks: - Latency: 59.5544ms desktop-ssqsibm.netbird.ftl.anon-1V9Bj.domain: NetBird IP: 100.125.72.59 Public key: dgiqGLPGw1pNGfNcE4ArFMNNnyrdUtN65mnPbj/UmDY= Status: Connecting -- detail -- Connection type: - ICE candidate (Local/Remote): -/- ICE candidate endpoints (Local/Remote): -/- Relay server address: Last connection update: 23 minutes, 46 seconds ago Last WireGuard handshake: - Transfer status (received/sent) 0 B/0 B Quantum resistance: false Networks: - Latency: 0s Events: [INFO] SYSTEM (777999db-d0da-4a2c-b1a8-0cde2cb716f4) Message: Network map updated Time: 1 hour, 34 minutes ago [INFO] SYSTEM (11838915-9e83-4ed6-8e1e-9f38c13f9271) Message: Network map updated Time: 1 hour, 30 minutes ago [INFO] SYSTEM (aae7ddec-8749-4abf-8019-645716d879ac) Message: Network map updated Time: 1 hour, 28 minutes ago [INFO] SYSTEM (b2d44ce6-55a1-4dba-9cd8-86327a8271ea) Message: Network map updated Time: 1 hour, 7 minutes ago [INFO] SYSTEM (aecf7265-695f-4d77-891a-6e4fded9a6ad) Message: Network map updated Time: 1 hour, 6 minutes ago [INFO] SYSTEM (03c65c1a-9b5c-42cd-b09d-6dd64bf4f632) Message: Network map updated Time: 41 minutes, 19 seconds ago [INFO] SYSTEM (0d562360-43bd-484c-95f8-3f8cd393e6bf) Message: Network map updated Time: 23 minutes, 46 seconds ago [INFO] SYSTEM (aae0d96d-1de1-44f8-8ccd-8cc66e88b83a) Message: Network map updated Time: 23 minutes, 34 seconds ago [INFO] SYSTEM (17ed1f3e-3e12-4117-a1a9-894ee874d543) Message: Network map updated Time: 21 minutes, 1 seconds ago [INFO] SYSTEM (a164c301-a996-4b46-9bed-c2ede804b3d8) Message: Network map updated Time: 20 minutes, 15 seconds ago OS: windows/amd64 Daemon version: 0.67.1 CLI version: 0.67.1 Profile: FTL-test1 Management: Connected to https://netbird.ftl.anon-1V9Bj.domain:443 Signal: Connected to https://netbird.ftl.anon-1V9Bj.domain:443 Relays: [stun:netbird.ftl.anon-1V9Bj.domain:3478] is Available [rels://netbird.ftl.anon-1V9Bj.domain:443] is Available Nameservers: FQDN: desktop-ssqsibm-116-4.netbird.ftl.anon-1V9Bj.domain NetBird IP: 100.125.116.4/16 Interface type: Userspace Quantum resistance: false Lazy connection: false SSH Server: Disabled Networks: - Peers count: 1/2 Connected Create and upload a debug bundle, and share the returned file key: netbird debug for 1m -AS -U *Uploaded files are automatically deleted after 30 days.* Alternatively, create the file only and attach it here manually: netbird debug for 1m -AS **Screenshots** If applicable, add screenshots to help explain your problem. **Additional context** Add any other context about the problem here. **Have you tried these troubleshooting steps?** - [x] Reviewed [client troubleshooting](https://docs.netbird.io/how-to/troubleshooting-client) (if applicable) - [x] Checked for newer NetBird versions - [x] Searched for similar issues on GitHub (including closed ones) - [x] Restarted the NetBird client - [x] Disabled other VPN software - [x] Checked firewall settings
saavagebueno added the triage-needed label 2026-08-05 01:30:28 -04:00
Author
Owner

@braginini commented on GitHub (Mar 28, 2026):

This is happening because they are not logging out of the IdP but netbird. You need to provide an appropriate log out URL in your OIDC configuration in Authentik.

In Authentik:
• Go to your NetBird application/provider
• Set:
• “Prompt” = login (OIDC)
• Or enforce re-authentication policies

This forces Authentik to show the login screen even if a session exists.

<!-- gh-comment-id:4148112905 --> @braginini commented on GitHub (Mar 28, 2026): This is happening because they are not logging out of the IdP but netbird. You need to provide an appropriate log out URL in your OIDC configuration in Authentik. In Authentik: • Go to your NetBird application/provider • Set: • “Prompt” = login (OIDC) • Or enforce re-authentication policies This forces Authentik to show the login screen even if a session exists.
Author
Owner

@klinkeye commented on GitHub (Mar 28, 2026):

This is happening because they are not logging out of the IdP but netbird. You need to provide an appropriate log out URL in your OIDC configuration in Authentik.

In Authentik: • Go to your NetBird application/provider • Set: • “Prompt” = login (OIDC) • Or enforce re-authentication policies

This forces Authentik to show the login screen even if a session exists.

Is there no SLO support in Netbird for OIDC?

<!-- gh-comment-id:4149279289 --> @klinkeye commented on GitHub (Mar 28, 2026): > This is happening because they are not logging out of the IdP but netbird. You need to provide an appropriate log out URL in your OIDC configuration in Authentik. > > In Authentik: • Go to your NetBird application/provider • Set: • “Prompt” = login (OIDC) • Or enforce re-authentication policies > > This forces Authentik to show the login screen even if a session exists. Is there no SLO support in Netbird for OIDC?
Author
Owner

@braginini commented on GitHub (Mar 30, 2026):

Is there no SLO support in Netbird for OIDC?

NetBird depends on Dex for that and it doesn't support it yet unfortunately. But there is some movement around that.

<!-- gh-comment-id:4152720427 --> @braginini commented on GitHub (Mar 30, 2026): > Is there no SLO support in Netbird for OIDC? NetBird depends on [Dex](https://github.com/dexidp/dex) for that and it doesn't support it yet unfortunately. But there is some movement around that.
Author
Owner

@jnfrati commented on GitHub (Apr 7, 2026):

Closing this for now, as there's no action on our side :/
Related issue in case anyone wants to keep track of this https://github.com/dexidp/dex/issues/3292

<!-- gh-comment-id:4198626006 --> @jnfrati commented on GitHub (Apr 7, 2026): Closing this for now, as there's no action on our side :/ Related issue in case anyone wants to keep track of this https://github.com/dexidp/dex/issues/3292
Author
Owner

@bitcrshr commented on GitHub (Apr 15, 2026):

Stumbled across this myself and have done some digging. If I'm not mistaken, with the new combined architecture it's no longer possible to disable Dex/swap it out for your own OIDC provider--Dex always acts as the middleman.

Do you think that supporting that swapout again is on the horizon, or are you hard-committed to Dex? I can understand the latter, probably provides the most value for the least maintenance burden.

On that note, I'm attempting to shim in the option to go "dex-less" with the combined architecture so I can support RP-Initiated Logout between my Authentik and Netbird instances.

If that goes well, would you be interested in a PR for that?

Edit: Looks like RP-Initiated Logout is coming to Dex soon anyhow, so probably not much sense in supporting what I mentioned. If I do have a successful patch, I'd be happy to share it in case anyone else wants to try it while we wait.

<!-- gh-comment-id:4255438145 --> @bitcrshr commented on GitHub (Apr 15, 2026): Stumbled across this myself and have done some digging. If I'm not mistaken, with the new combined architecture it's no longer possible to disable Dex/swap it out for your own OIDC provider--Dex always acts as the middleman. Do you think that supporting that swapout again is on the horizon, or are you hard-committed to Dex? I can understand the latter, probably provides the most value for the least maintenance burden. On that note, I'm attempting to shim in the option to go "dex-less" with the combined architecture so I can support RP-Initiated Logout between my Authentik and Netbird instances. ~~If that goes well, would you be interested in a PR for that?~~ Edit: [Looks like RP-Initiated Logout is coming to Dex soon](https://github.com/dexidp/dex/issues/4560) anyhow, so probably not much sense in supporting what I mentioned. If I do have a successful patch, I'd be happy to share it in case anyone else wants to try it while we wait.
Author
Owner

@jnfrati commented on GitHub (Apr 16, 2026):

Hey @bitcrshr!

Just in case, RP-Initiated logout is also comming into Netbird pretty soon 😉 https://github.com/netbirdio/netbird/pull/5804

<!-- gh-comment-id:4260159355 --> @jnfrati commented on GitHub (Apr 16, 2026): Hey @bitcrshr! Just in case, RP-Initiated logout is also comming into Netbird pretty soon 😉 https://github.com/netbirdio/netbird/pull/5804
Author
Owner

@wvanl commented on GitHub (Jul 15, 2026):

To me its looking like the RP-Initiated logout forgot the sessionStorage.removeItem('oidc.default'); part before redirecting to the idp, if it has been added.
Since I just get sent to the idp for logout, but going back to netbird it is still logged in using the jwt access token saved in sessionStorage.

<!-- gh-comment-id:4978656007 --> @wvanl commented on GitHub (Jul 15, 2026): To me its looking like the RP-Initiated logout forgot the sessionStorage.removeItem('oidc.default'); part before redirecting to the idp, if it has been added. Since I just get sent to the idp for logout, but going back to netbird it is still logged in using the jwt access token saved in sessionStorage.
Sign in to join this conversation.
No Label triage-needed
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: DYNR/netbird#11686