mirror of
https://github.com/netbirdio/netbird.git
synced 2026-08-04 19:55:09 -04:00
Request failed with status code 401. Error: token invalid #986
Open
opened 2025-11-20 05:21:02 -05:00 by saavagebueno
·
36 comments
No Branch/Tag Specified
main
android/gui-integration
revert/component-types
feat-post_quantum_ml_kem
ice-stun-wg-demux
dependabot/npm_and_yarn/proxy/web/npm_and_yarn-b39864987c
agent-network-setup-poc
dependabot/go_modules/aws-sdk-8f849ebaed
dependabot/github_actions/actions-a940c7c866
dependabot/go_modules/otel-e34c790afd
dependabot/go_modules/testcontainers-de325c0dd6
dependabot/go_modules/wireguard-dbd6b95108
dependabot/go_modules/pion-5f703e1eca
dependabot/go_modules/gorm-2271c8195b
fix-login-needed-check
dependabot/go_modules/google.golang.org/grpc-1.82.1
fix/ui-gtk3-support
enterprise-traefik-and-migration-fixes
disambiguate_p2p_metrics
revert/component-types-hookup
embedded-vnc
feature/ios-ssh
docs/agent-network-docs-update
dependabot/go_modules/github.com/aws/aws-sdk-go-v2/service/s3-1.106.3
dependabot/go_modules/github.com/pion/stun/v3-3.1.5
fix-ssh-authorized-users-multi-rule
peer-acl-multi-source
reverse-proxy-crowdsec-appsec
reverse-proxy-allow-match-or
client-local-metrics
lazy-conn-per-peer
lazy-conn-rosenpass
dependabot/go_modules/github.com/gopacket/gopacket-1.7.0
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.6
dependabot/go_modules/github.com/pires/go-proxyproto-0.15.0
dependabot/go_modules/github.com/jackc/pgx/v5-5.10.0
dependabot/go_modules/github.com/oapi-codegen/runtime-1.6.0
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.4
dependabot/go_modules/github.com/pkg/sftp-1.13.11
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.20.0
ssh-windows-privilege-check
fix/explicit-cors-handling
fix/remove-math-rand
test/gui-memory-leak-fix
fix/ui-status-dispatch
install-script-ui-dependencies
fix/grpc-get-network-map
fix/subscribe-status-coalesce
fix/tray-menu-item-leak
fix/windows-tray-race
feature/changeset
worktree-dns-route-qtype-fallthrough
mdm_integration
mlsmaycon-patch-2
feat/agent-network-ollama
proxy-tunnel-cache-ttl-env
coderabbitai/utg/1e5b0a5
grpc-acl
test/battery-drain
components-impl-drop-indexes-use-xids-no-resource-policy-map
fix/nmap-relevant-groups
e2e-guardrail-blocks-unselected-model
fix/lazyconn-cold-start-allowed-ips
vertex-guardrails-model-access-e2e
add-atomic-cache-ops
refactor/relay-foreign-cache
ci/trigger-release-tests
feature/kimi-3-agent-networks-dns-warmup
feature/dns-lazy-conn-warmup
daemon-ipc-acl
feature/ui-translation-key-parity-check
refactor/relay-foreign-cache-tests
fix/lazyconn-idle-keep-wg-peer
dmitri-propagate-auth-grant-types-on-combined
0.74.7-branch
diagnose-empty-vs-corrupt-state
windows-sleep-detector
fix/cli-up-wait-for-daemon
rp_key_persistency
feature/native-grpc
0.74.6-branch
0.74.6-branch-sync
0.74.5-branch-sync
0.74.4-branch
fix/remove-stale-peers-removal
fix/remove-stale-proxy-logic
fix/nsis-preserve-autostart-on-upgrade
refactor/peer-event-bus
dependabot/go_modules/goauthentik.io/api/v3-3.2026050.3
dependabot/go_modules/github.com/pkg/sftp-1.13.10
components-impl-drop-indexes
fix-reset-aggregation-window-flake
dependabot/go_modules/github.com/pion/dtls/v3-3.1.5
0.74.x
fix/relay-states-lock
update-process-pkg
update-gopsutil-v4
fix/relay_states_lock
increase-sysinfo-timeout
dependabot/go_modules/github.com/Azure/go-ntlmssp-0.1.1
dependabot/go_modules/github.com/eko/gocache/store/redis/v4-4.2.6
dependabot/go_modules/github.com/eko/gocache/lib/v4-4.2.3
fix/fail-to-create-upnp-port-mapping-on-opnsense-firewall
0.74.3-branch
fix/routeselector-atomic-exit-node
netmap_progressive_alignment
nmap/components-impl
dependabot/go_modules/github.com/jackc/pgx/v5-5.9.2
dependabot/go_modules/github.com/oapi-codegen/runtime-1.4.2
dependabot/go_modules/github.com/gopacket/gopacket-1.6.1
dependabot/go_modules/github.com/coreos/go-oidc/v3-3.19.0
dependabot/go_modules/github.com/pires/go-proxyproto-0.12.0
fix/signal-watchdog-sync-stop
docs/agent-network
test/affected-logic
fix/revert-ice-filter
refactor/simplify-affected-peers
pascal-filter-policies-by-direction
claude/lock-contention-peer-connect-g8t6au
dmitri-filter-policies-by-direction
refactor/migrate-profiles-to-go
profile-bindings-ios
fix/skip-restart-unchanged-route
fix/mgmt-cache-async-resolve
refactor/wails-update-105
client_lifetime_serialization_refactor
fix/browser-ssh-2
fix/ipv6-and-netstack-accept-loop
fix/browser-ssh
profile-id-name-test
refactor/mgmt-bootstrap
feat/getting-started-unified-wizard
socket-grpc-permissions
fix/mysql-index-migration
windows-dns-firewall
tests/enable-race-on-tests
ui-refactor-gtk3
feature/affected-peers-grpc
profile-id
lazyconn-first-packet-fix-v2
claude/focused-gates-VMTgb
ui-tray-linux-leftclick
fix/ctx-enrichment
daemon-owner
feature/android-client-ssh
worktree-accept-ra-forwarding
nmap/combined-deploy
task/align_protobuff_toolset
feature/session-extend
add-json-yaml-flags
refactor/ephemeral-cleanup
claude/webtransport-relay-wasm-mUjY9
claude/vnc-udp-feasibility-6KB1U
fix/wgport-config
e2e-windows-dns-combined
fix/login-cmd-root-flags
feat/reseller-openapi-spec
github-issue-resolver
add-steamos-support
fix-darwin-uninstaller
flutter-test
ci/freebsd-pkg-bootstrap
cached-serial-check-on-sync
fix-mgmt-cache-bypass-overlay
revert-easyjson-5938
revert-ice-5820
revert-firewalld-5928
refactor/permissions-manager
revert-dns-5935-systemd-resolved
revert-dns-5935-5945
revert-dns-5945-mgmt-cache
feature/log-most-busy-peers
prototype/ui-wails
coderabbitai/utg/8ae8f20
feature/use-peer-fqdn-on-https
release/0.68.3
add-slack-channel
claude/rdp-token-passthrough-eNcqW
transparent-proxy
fix/macos-stale-route-eexist
crowdsec-selfhosted
fix/remove-otel-units
entire/checkpoints/v1
fix/getting-started
feat/static-connectors-combined-server
feature/use-local-keys-embedded
feature/fleetdm
set-env-only-if-not-fork
feature/expose-has-channel
fix/connection-status-race
fix/filter-cgnat-cni-ice-candidates
feature/check-cert-locker-before-acme
test/proxy-fixes
test/proxy-mtu
prototype/ui-tauri
test/proxy-speed
fix-reused-ports
feat/migrate-to-embedded-idp
feature/add-serial-to-proxy-merged
deploy/proxy-serial
test/connection
feature/disable-legacy-port
feature/flag-to-disable-legacy-port
test/perftest
fix/http-redirect
poc-token-command
dn-reverse-proxy
prototype/reverse-proxy-rename
prototype/reverse-proxy-logs-pagination
feature/client-metrics
prototype/reverse-proxy-clusters
debug-dns-route
fix/win-dns-batch
add-extra-route-logs
job-stream-notify-disconnection-eof
deploy/secrets-manager
trigger-proxy-update
bug/update-ios-client-code-build-tags
sync-client-netmap-serial
log/conn-disconn
nmap/compaction-deploy
ci-win-test
feature/disk-encryption-check
wasm-debug
swap-dns-prio
fix/dex-config
feature/migrate-auto-groups-to-table
nmap/compaction
dex-nocgo-stub
feature/exclude-terraform-from-rate-limiting
test-freebsd
retries-refactor
coderabbitai/docstrings/b7e98ac
feat/integrate-zitadel
bug/ios-hanging-reconection
zitadel-idp
feat/network-map-serial
refactor/get-account-no-users
feat/auto-upgrade
feature/report-high-pat-id
feature/temporary-access-for-resource
fix/nmap-fwrules
dont-restart-dns
prototype/ui
update-gomobile
go-dns-for-ice
wasm-ldflags
test-ldflags
wasmbuild-test
feature/networks-s2s
vk/compare-nmaps
dbg/bothmaps
reorder-dns-shutdown
fix/relay-reconnection-race
fix/nmap-exitnodes
vk/debug/nmap-both
move-licensed-code
feat/better-daemon-connection-lost-message
feat/auto-update-2
test/timings
refactor/getaccount-raw
tests/nmap-getaccount
refactor/nmap
refactor/nmap-limit-buffer
feature/detect-mac-wakeup
feature/extract-modules
quick-setings
feat/sync-limiter
feature/store-cache-impl
fix-install-version
feature/store-metrics
feature/metrics-on-store
feature/use-gorm-cache
loadtest-signal
unsymmetrical-squash
refactor/reducate-signaling
test/update-reduce
feature/store-cache
feature/remote-debug
cli-ws-proxy-backend-addr
feat/mgmt-map-serial
snyk-fix-d9d0081a4c7f9137bdb59d0d50a141a2
snyk-fix-7415cea5a11acd66753540ca2c598c63
job-yml-update
feature/android-allow-selecting-routes
fix/up-sequence
fix/dns-hash-update
snyk-fix-967adae9863f17f108ce8948d9117b8d
log/getaccount-by-peer
signal-suppressor
dns-exit-node
feature/auto-updates
feature/cache-srv-key
merged-fixes
fix/missed-offers-and-debug
debug-and-fixes
poc-wasm-clean-backend-s2s
test/remote-debug
debug-api
fix/remove-gpo-if-empty
fix/test-freebsd
fix/mysql-setup
fix/remove-logout-btn
handle-existing-domain-user
chore/unify-domain-validation
snyk-fix-c5fafc8a50ce1f29046e25a1fc346185
feat/profile-edit-btn
snyk-fix-a54966211e18d4cf67e5a2757cc006d1
log-short-id
feat/logout-ephemeral
log-checks
batch-wg-ops
nb-interface-default
feat/aws-integration
add/race-test
feature/relay-feature-versioning
fix/systemd-service-logs
poc/preprocessed-map
add-account-onboarding
bind-ipv6
fix/merge-main
logs/peerlogs-addpeer
feature/net-297-network-migration
feature/support-skip-auto-apply-exit-node-routes
set-cmd
set-command-with-cursor
feature/limit-update-channel
stop-using-locking-share
feature/poc-lazy-detection
feature/net-248-removal-of-sync-mutex-locks
test/multiple-peer-logging
preresolve
add-ns-punnycode-support
apply-routes-early
windows-search-domains
fix/connecting-route-filter
feature/management/rest-client/impersonate
debug-local-records
resource-fields-snake-case
test/grpc-rate-limit
traffic-correlation-policy
feature/rest-client-options
feat/events-metrics
feature/buf-cli
test/add-ratelimiter
test/remove-write-lock-on-add-peer
fix/add-peer-semaphore
feature/users-roles-endpoint
mlsmaycon-patch-1
debug-user-role
chore/primary-key-on-networks
feature/update-account-peers-buffer-startup
remove-ubuntu2004-runners
refactor/permissions-no-pat-allowed
ref/logrus-factory
use-conntrack-zone
deploy/permissions-account
feature/lazy-connection-idle
ref/improve-test-cov
restore-pr-3440
test/increase-grpc-timeouts
feat/buffer-account-peers-update
test/networkmapgeneration-changes
feature/base-manager
feature/flow-receiver
chore/benchmark-with-large-runner
refactor/handshake-initiator
client/ui-update-systray-icons
userspace-router
wgwatcher-test
output-if-key-already-exists
fix/relay-reconnection
feature/port-forwarding-client-codecleaning
detached2
test/callbacks-nil-iceconninfo
refactor/optimize-peer-expiration
enable-udp-port-for-docker-template
fix/relay-update
feature/apply-posture-netmap
fix/group-update-existing-resource
conntrack-stats
upgrade-okta-sdk
multi-price
test/conn-stat
set-min-parallel-tests-for-management
dns-interceptor
debug-dns
router-dns
add-static-system-info
debug-0.29.4
debug-0.33.0
account-refactoring
relay/2800_quic
route-get-account-refactoring
test/seed-random-routes
feature/get-account-refactoring
test/reconnect-race-condition
refactor/get-account-usage
feature/add-session-id-to-update-channel
improve-ipv4conn
fix/async-pion-event-handling
debug
add-offload
feature/validate-group-association-debug
fix/limit-conn-for-sqlite
test/engine-iface
test/transaction-for-jwt-sync
fix/engine-stop-in-foreground
feature/add-mysql-support
test-migration
refactor/header-size-values
relay/eliminate-gob
test/signal-dispatcher-with-relay
relay/debug
validate-icon
feature/ipv6-support
use-pre-expanded-peers-map
feature/use-signal-dispatcher
validate/peer-status
add-read-write-times
fix/sync-peer-race
feature/relay-status
netmap
evaluate/network-map-hash
fix/lower-dns-resolve-interval-on-fail
feature/relay
fix/go-mod-version
upgrade-nftables
synology-userspace-mode
fix/use-ip-for-default-routes-on-darwin
fix/proxy_close
enable-release-workflow-on-pr
deploy/peer-performance
feature/permanent-turn
feature/permanent-turn-proxy
deploy/posture-check-sqlite
feature/optimize_sqlite_save
debug-ios-behavior
fix/delete-route-only-after-adding
tshoot/windows-logger
remove-new-routing
refactor/eliminate-repo-dependency
add-arm-to-ci
refactor-demo-account-object
test/abc2
test/abc
send-ssh-rosenpass-config-meta
refactor-demo
ensure-schedule-never-runs-non-positive
feature/peer-validator-groupmgm
feature/peer-validator-fix
fix/include-active-dashboard-users
fix/handle-canceling-schedule
fix/geo-download
debug-google-workspace
yury/resolve-ip-to-location
feature/extend-sysinfo
sqlite-async-peer-status
yury/add-postgresql-store
fix/route
test-build
posture-checks-poc
debug-keycloak-idp
poc/netstack
for-pascal-tmp
peer-logout-management
manual-peer-logout
detached
chore/refactor-management
test/dns-bind
fix/enforce-acl-for-containers
yury/use-sync-map-in-updatechannel
fix/events-key-handling
filter-cache-on-load-account
fix/user-expiration
handle-user-context-cancellation
nb-client-k8s-statefulset
fake-addr
fix/iptables_in_docker
ebpf-debug
update-getting-started-flow-use-postgres
fix/peer_list_notification
feature/device-authentication-with-client-secret
feature/keep_alive
feat-groups-from-jwt
separate_proxy_from_wgconfig
fix/wg_conn
wg_conn_fix
wg_bind_parallel_processing
fix-rollback-get-acls
proxy_cfg_cleanup
performance-improvement-rego
update-lock-log-level
feat-client-side-acl
refactor/move_grpcserver_logic_to_account_manager
feature/event-storage
feature/update-idp-redeeming-invite
feature/api-peer-info
return-groupminimum-setupkey
feature/interface-bind
documentation_enhancement
fix-peer-registration
ssh
users_cache
pass-client-caller
client_caller_type
revert-283-feat-fix-windows-installer
periodic-peer-updates
ebpf
braginini/wasm
v0.76.1
v0.76.0
v0.75.1
v0.75.0
v0.74.7
v0.74.6
v0.74.5
v0.75.0-rc.6
v0.74.4
v0.74.3
v0.75.0-rc.5
v0.74.2
v0.74.1
v0.75.0-rc.4
v0.74.0
v0.74.0-rc.2
v0.74.0-rc.1
v0.73.2
v0.75.0-rc.3
v0.75.0-rc.2
v0.73.1
v0.75.0-rc.1
v0.73.0
v0.72.4
v0.72.3
v0.72.2
v0.72.1
v0.72.0
v0.71.4
v0.71.3
v0.71.2
v0.71.1
v0.71.0
v0.70.5
v0.70.4
v0.70.3
v0.70.2
v0.70.1
v0.70.0
v0.69.0
v0.68.3
v0.68.2
v0.68.1
v0.68.0
v0.67.4
v0.67.3
v0.67.2
v0.67.1
v0.67.0
v0.66.4
v0.66.3
v0.66.2
v0.66.1
v0.66.0
v0.65.3
v0.65.2
v0.65.1
v0.65.0
v0.64.6
v0.64.5
v0.64.4
v0.64.3
v0.64.2
v0.64.1
v0.64.0
v0.63.0
v0.62.3
v0.62.2
v0.62.1
v0.62.0
v0.61.2
v0.61.1
v0.61.0
v0.60.9
v0.60.8
v0.60.7
v0.60.6
v0.60.5
v0.60.4
v0.60.3
v0.60.2
v0.60.1
v0.60.0
v0.59.13
v0.59.12
v0.59.11
v0.59.10
v0.59.9
v0.59.8
v0.59.7
v0.59.6
v0.59.5
v0.59.4
v0.59.3
v0.59.2
v0.59.1
v0.59.0
v0.58.2
v0.58.1
v0.58.0
v0.57.1
v0.57.0
v0.56.1
v0.56.0
v0.55.1
v0.55.0
v0.54.2
v0.54.1
v0.54.0
v0.53.0
v0.52.2
v0.52.1
v0.52.0
v0.51.2
v0.51.1
v0.51.0
v0.50.3
v0.50.2
v0.50.1
v0.50.0
v0.49.0
v0.48.0-dev2
v0.48.0
v0.47.2
v0.47.1
v0.47.0
v0.46.0
v0.45.3
v0.45.2
v0.45.1
v0.45.0
v0.44.0
v0.43.3
v0.43.2
v0.43.1
v0.43.0
v0.42.0
v0.41.3
v0.41.2
v0.41.1
v0.41.0
v0.40.1
v0.40.0
v0.39.2
v0.39.1
v0.39.0
v0.38.2
v0.38.1
v0.38.0
v0.37.2
v0.37.1
v0.37.0
v0.36.7
v0.36.6
v0.36.5
v0.36.4
v0.36.3
v0.36.2
v0.36.1
v0.36.0
v0.35.2
v0.35.1
v0.35.0
v0.34.1
v0.34.0
v0.33.0
v0.32.0
v0.31.1
v0.31.0
v0.30.3
v0.30.2
v0.30.1
v0.30.0
v0.29.4
v0.29.3
0.29.3
v0.29.2
v0.29.1
v0.29.0
v0.28.9
v0.28.8
v0.28.7
v0.28.6
v0.28.5
v0.28.4
v0.28.3
v0.28.2
v0.28.1
v0.28.0
v0.27.10
v0.27.9
v0.27.8
v0.27.7
v0.27.6
v0.27.5
v0.27.4
v0.27.3
v0.27.2
v0.27.1
v0.27.0
v0.26.7
v0.26.6
v0.26.5
v0.26.4
v0.26.3
v0.26.2
v0.26.1
v0.26.0
v0.25.9
v0.25.8
v0.25.7
v0.25.6
v0.25.5
v0.25.4
v0.25.3
v0.25.2
v0.25.1
v0.25.0
v0.24.4
v0.24.3
v0.24.2
v0.24.1
v0.24.0
v0.23.9
v0.23.8
v0.23.7
v0.23.6
v0.23.5
v0.23.4
v0.23.3
v0.23.2
v0.23.1
v0.23.0
v0.22.7
v0.22.6
v0.22.5
v0.22.4
v0.22.3
v0.22.2
v0.22.1
v0.22.0
v0.21.11
v0.21.10
v0.21.9
v0.21.8
v0.21.7
v0.21.6
v0.21.5
v0.21.4
v0.21.3
v0.21.2
v0.21.1
v0.21.0
v0.20.8
v0.20.7
v0.20.6
v0.20.5
v0.20.4
v0.20.3
v0.20.2
v0.20.1
v0.20.0
v0.19.0
v0.18.1
v0.18.0
v0.17.0
v0.16.0
v0.15.3
v0.15.2
v0.15.1
v0.15.0
v0.14.6
v0.14.5
v0.14.4
v0.14.3
v0.14.2
v0.14.1
v0.14.0
v0.13.0
v0.12.0
v0.11.6
v0.11.5
v0.11.4
v0.11.3
v0.11.2
v0.11.1
v0.11.0
v0.10.10
v0.10.9
v0.10.8
v0.10.7
v0.10.6
v0.10.5
v0.10.4
v0.10.3
v0.10.2
v0.10.1
v0.10.0
v0.9.8
v0.9.7
v0.9.6
v0.9.5
v0.9.4
v0.9.3
v0.9.2
v0.9.1
v0.9.0
v0.8.12
v0.8.11
v0.8.10
v0.8.9
v0.8.8
v0.8.7
v0.8.6
v0.8.5
v0.8.4
v0.8.3
v0.8.2
v0.8.1
v0.8.0
v0.7.1
v0.7.0
v0.6.4
v0.6.3
v0.6.2
v0.6.1
v0.6.0
v0.5.11
v0.5.10
v0.5.1
v0.5.0
v0.4.0
v0.3.5
v0.3.4
v0.3.3
v0.3.2
v0.3.1
v0.3.0
v0.2.3
v0.2.2-beta.1
v0.2.1-beta.5
v0.2.0-beta.5
v0.2.0-beta.4
v0.2.0-beta.3
v0.2.0-beta.2
v0.2.0-beta.1
v0.1.0-beta.3
v0.1.0-beta.2
v0.1.0-beta.1
v0.1.0-rc.2
v0.1.0-rc-1
v0.0.8-hotfix-1
v0.0.8
v0.0.7
v0.0.6
v0.0.5
v0.0.4
v0.0.3
v0.0.2
v0.0.1
v0.0.0
Labels
Clear labels
2021 Q4
2022 Q1
2022 Q1
accessibility
acl
agent
agent
Android
Android
api
authentik
automation
azure
battery-usage
bug
cache
client
client-ui
cloud
cloud-only
cloudflare
community
compatibility
config-idp
config-issue
connection
contribution
coturn
cross-vpn
dashboard
data-usage
distribution
dns
docker
documentation
duplicate
enhancement
enhancement
event-stream
feature-request
freebsd
getting-started
go
good first issue
gui
help wanted
home-assistant
idp
inconsistency
integration
integrations
ios
ipv6
jwt
k8s
keycloak
linux
login
macos
management-service
missing-docs
mobile
moved-internal
needs-review
netbird-ui
networking
new-platform
nginx
notification
okta
openwrt
packaging
peer-management
peer-management
peer-management
performance
postgres
posture-checks
psk
pull-request
question
refactor
relay
release
rfc
routes
security
security-related
self-hosting
server
signal
sleep-issue
ssh
ssl
status
store
synology
system-compatibility-issue
test-suite
third-party-integration
triage
triage-needed
troubleshooting
UX
waiting-feedback
windows
wontfix
zitadel
Mirrored from GitHub Pull Request
Milestone
No items
No Milestone
Projects
Clear projects
No project
Assignees
saavagebueno
Clear assignees
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: SVI/netbird#986
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Delete Branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Originally created by @Unreeling8562 on GitHub (Jun 16, 2024).
Describe the problem
I installed Netbird with keycloak as idp. When I try to login I get the following error:
Request failed with status code 401. Error: token invalid
In docker logs:
To Reproduce
Steps to reproduce the behavior:
Expected behavior
I should see the dashboard after logging in
Are you using NetBird Cloud?
No, selfhosted on Hetzner X22
NetBird version
0.27.10
Screenshots
Additional context
Here is my setup.env:
@Unreeling8562 commented on GitHub (Jun 16, 2024):
I've followed the official advanced docs from Netbird
@Cikaros commented on GitHub (Jun 16, 2024):
It requires the Geo database to be installed. Check whether the database is installed.
https://docs.netbird.io/selfhosted/geo-support
@Unreeling8562 commented on GitHub (Jun 17, 2024):
I've installed this, but still the same error unfortunately
@allroundtechie commented on GitHub (Jun 17, 2024):
I can imagine this is the same issue like this one (except this one is about Zitadel as an IDP): https://github.com/netbirdio/netbird/pull/2089
I doubt a 401 token invalid error has something to do with the geo database.
@Cikaros commented on GitHub (Jun 17, 2024):
Check the logs of the management service
@HansAschauer commented on GitHub (Jun 21, 2024):
I had a problem with quite similar symptoms. This is possibly a bug in recent versions of keycloak, but I am not an expert with it.
However, I could work around the issue in the following way:
In the setup guide (https://docs.netbird.io/selfhosted/identity-providers#step-6-create-a-net-bird-client-scope), go to step 6 ("Create a NetBird client scope"). But instead of adding "netbird-client" to "Included Client Audience", add it to "Included Custom Audience"
In fact, I have created a second mapper with these settings, but I guess just changing the first one should be enough.
If you want to check if the audience is set correctly, go to Clients -> netbird-client, go to tab "Client Scopes", subtab (one line below) "evaluate". Choose the user netbird and select "Generated access tokens" in the list on the right. Check if the "aud" claim contains "netbird-client".
@ergleb78 commented on GitHub (Jun 27, 2024):
We are experiencing the same issue on Google Auth. Management logs:
It's inconsistent: sometimes restart of docker-compose helps, sometimes it required to remove the containers and recreate
UPDATE: Downloading and updating GEO database fixed the issue.
Ask: It would be incredibly helpful to see some pointers to the root cause of the problem in the err logs.
@Vandaahl commented on GitHub (Jun 28, 2024):
Just wanted to say thank you for this comment. I wasted so many hours getting this to work with Keycloak and now it finally works :)
@Pshemas commented on GitHub (Jul 2, 2024):
I have similar problem with Authentik. Initially the setup worked, but after restarting the containers for both Netbird and Authentik I get this dreaded
401: token invaliderror.After restarting the containers (both for Authentik and Netbird) I can't log in to management portal. Any suggestions what to do are greatly appreciated.
Error logs found in management component:
Docker Compose file:
Environment variables file:
I've also checked Authentik and I found "application authorized" event:
@vsavovski commented on GitHub (Jul 3, 2024):
Regarding Keycloak, it is possible to use the original setup; however, you cannot provide
netbird-clientas the ID. Instead, you must use the generated GUID that Keycloak creates for each client ID.You can find the GUID in the URL:
https://keycloak.mysite.com/admin/master/console/#/{realm}/clients/{client-id}.Alternatively, as @HansAschauer mentioned, you can generate access tokens and locate the client ID in the
audfield. This client ID should then be used in the .env file.@Pshemas commented on GitHub (Jul 3, 2024):
so far I've tried:
NETBIRD_MGMT_IDP_SIGNKEY_REFRESH=trueadded to .envhttps://github.com/netbirdio/netbird/issues/1531#issuecomment-1929102315
https://github.com/netbirdio/netbird/issues/2142#issuecomment-2172029587
This doesn't help sadly. IWhen I look into developer console I see this:
And token invaild in netbird management logs as posted above.
I wonder - can it be something with Authentik being behind Cloudflare? But on the other hand it does not cause any issues on other apps I use with Authentik (and the super annoying thing is that it worked for a couple of weeks without a hitch).
@Pshemas commented on GitHub (Jul 4, 2024):
on my end it "autmagically" started working - thus suggesting something to do with Authentik config, not Netbird itself.
@identw commented on GitHub (Jul 4, 2024):
I have the same problem but with Dex. Right after starting netbird-management, everything works and the login succeeds. However, if I wait a couple of hours, I get the same error upon login:
@mlsmaycon commented on GitHub (Jul 4, 2024):
@identw you need to enable sign key refresh with
--idp-sign-key-refresh-enabledAfter that run
docker compose up -d@identw commented on GitHub (Jul 5, 2024):
@mlsmaycon Thank you very much. This helped me
@singhera-ilmiya commented on GitHub (Jul 5, 2024):
I'm still getting same issue please help me @mlsmaycon @identw
@mlsmaycon commented on GitHub (Jul 5, 2024):
@singhera-ilmiya can you check your management logs for error logs and share them with us?
@bl0way commented on GitHub (Jul 6, 2024):
Indeed, this worked for me. The previous proposed solution unfortunately was not working for me (keycloak didn't add the provided
Included Custom Audiencein the generated token for X or Y reasons). I modified themanagement.jsonto update theAuthAudienceby the generated GUID of keycloak.@adriangabura commented on GitHub (Jul 11, 2024):
Is it possible these 401 issues are related to this? I have triple checked my Azure config. There is no error on my part. And far too many identity providers cause similar symptoms.
@loso2255 commented on GitHub (Jul 20, 2024):
i think i found the same problem with zitadel
note: i'm using the latest version, docker stack
@mannp commented on GitHub (Jul 20, 2024):
For me it was resolved by changing the type of jwt signature being used.
@maslyankov commented on GitHub (Aug 3, 2024):
For me this issue was fixed with this:
https://github.com/netbirdio/netbird/issues/2142#issuecomment-2182390323
Basically In keycloak I configured :
Client scopes > Client scope details > Mapper details
Move "netbird-client" from "Included Client Audience ()" to "Included Custom Audience" leaving "Included Client Audience ()" .
@maze-st commented on GitHub (Oct 1, 2024):
Anyone found a solution with Zitadel?
@dark-vex commented on GitHub (Nov 18, 2024):
@maze-st not sure if it could be the same issue for you but in my case the problem was due to ufw firewall.
Basically it was preventing
netbird-managementcontainer to reachzitadel. Only during the reboot of the host netbird management container was able to reach zitatel (most likely because ufw was not yet started) but during the renewal of the token since ufw was blocking the connection, the token could not be renewed an causing the issue.I didn't had the time to investigate further but I've ended-up in disabling ufw firewall and manually creating the firewall rules that I need with iptables.
@PapaZigE commented on GitHub (Nov 18, 2024):
@maze-st, After updating, upgrading and restarting my server, I too was receiving the 401 "Invalid Token" & "Invalid Client" issue. Now, I'm not sure if my fix is applicable but I realized that my Service Account User in Zitadel was appended with the domain of my instance. This (I believe) is what broke the connection between the two. So I deleted the old SA User, followed the instructions to set it back up here: https://docs.netbird.io/selfhosted/identity-providers#zitadel and updated my management.json file in the following section:
After that, the issue went away, but so did all my data since I removed the volumes :(
I do think this was all because I clicked on check box in Domain Settings that says "Add organization domain as suffix to loginnames". I realized I didn't actually want that so I unchecked it but Zitadel didn't revert things back to normal hence recreating the SA User. Hopefully that's a fix for you! Luckly it didn't require reinstalling everything but just the SA User.
@wbarnard81 commented on GitHub (Nov 22, 2024):
Netbird and Authentik here.
Updated to Authentik 2024.10.4 this morning and now I am faced with the same error.
@Hutch79 commented on GitHub (Nov 26, 2024):
I also use Authentik and get the same error as @wbarnard81
I already needed to change the redirect uri since the UI changed.

It works with regex, but NOT with strict (which seams to be the default).
After that everything worked agains untill i updated netbird.
Unfortunatelly i don't know my old Netbird version.
@wbarnard81 commented on GitHub (Nov 26, 2024):
@Hutch79 Check here, it helped me solve the problem.
@Hutch79 commented on GitHub (Nov 26, 2024):
Thanks for the link @wbarnard81 !
Unfortunately, adding the API to scopes did not solve it for me...
@ne0YT commented on GitHub (Dec 16, 2024):
this fixed it for me (1st part):
https://github.com/netbirdio/netbird/issues/1657#issuecomment-2127732511
@krawiec commented on GitHub (Mar 23, 2025):
OMG i was struggling with this token issue for past 2 days
but i am using authentik, not keykloak
finally i figured there is issue with provider configuration
in documentation there is no mention about mappings, at all
so default ones are
authentik default OAuth Mapping: OpenID 'email'
authentik default OAuth Mapping: OpenID 'openid'
authentik default OAuth Mapping: OpenID 'profile'
i also added those two and suddenly everything started to work as expected
authentik default OAuth Mapping: OpenID 'offline_access'
authentik default OAuth Mapping: authentik API access
Please update documentation
@HammyHavoc commented on GitHub (May 27, 2025):
Still seeing this problem after adding
authentik default OAuth Mapping: OpenID 'offline_access'andauthentik default OAuth Mapping: authentik API access.Was working great until it wasn't. The tunnel is still running as I can connect to it via the Android phone app, but can't seem to sign into the web dashboard. Switching from
stricttoregexfixed theRedirect URI Error. The request fails due to a missing, invalid, or mismatching redirection URI (redirect_uri).problem I was seeing on Authentik, but now I'm stuck on getting aRequest failed with status code 401. Error: Token invaliderror when attempting to access the web dashboard after authenticating via Authentik.@HammyHavoc commented on GitHub (May 28, 2025):
11h of troubleshooting later. Heh!
Silliest thing in the world. The
management.jsonhas the following:Essentially, don't put the NetBird service account login password in there that you set when creating the service account. Set an app password (
service-account-netbird-password) in Authentik for the service account then add that to your config and give the container stack a restart. Boom. Back up and running now! :- ) Chuffed.@darwinmktech commented on GitHub (Jun 2, 2025):
Hi guys, for the token authencation issues for the zitadel, here's how i solve it without delete the volume and restart back.
Problem Description:
After enabling "Add organization domain as suffix to loginnames" in Zitadel, NetBird shows:
❌ 401 Unauthorized
❌ client not found
❌ token invalid
Root Cause:
The setting changes service account username from netbird-service-account to netbird-service-account@yourdomain.com, breaking the connection.
🛠️ Solution Steps:
Step 1: Generate New Client Credentials in Zitadel
Access Zitadel Console: https://your-netbird-domain.com/ui/console
Navigate to: Users → Service Accounts
Find your NetBird service account (likely named netbird-service-account@yourdomain.com)
Go to: Action -> Generate new Client Secret
Copy the new credentials:
ClientID: netbird-service-account@yourdomain.com
ClientSecret: [generated-secret]
Step 2: Update NetBird Management Configuration
cd /path/to/netbird
find . -name "management.json" -o -name "*.json" | xargs grep -l "ClientID"
nano management.json
Update the configuration:
{
"IdpManagerConfig": {
"ManagerType": "zitadel",
"ClientConfig": {
"Issuer": "https://your-netbird-domain.com",
"TokenEndpoint": "https://your-netbird-domain.com/oauth/v2/token",
"ClientID": "netbird-service-account@yourdomain.com", -- this part change with your new client id
"ClientSecret": "YOUR-NEW-CLIENT-SECRET-HERE", -- same goes to here
"GrantType": "client_credentials"
}
}
}
management.json
Step 3: Restart NetBird Services
docker-compose restart management
docker-compose restart dashboard
Step 4: Clear Cache & Test
Clear Cloudflare cache (if using Cloudflare)
Clear browser cookies for your NetBird domain
Test access: https://your-netbird-domain.com
🔍 Verification:
Check logs for success:
docker-compose logs management | tail -10
Copy
Should see: ✅ management server version X.X.X ✅ warmed up IDP cache with X entries ✅ No 401 or "client not found" errors
⚠️ Prevention:
To avoid this issue:
Don't enable "Add organization domain as suffix to loginnames" unless you have multiple organizations
If you must enable it, update NetBird config immediately after.
🆘 Alternative: Fresh Setup
If the above doesn't work:
docker-compose down
docker volume rm $(docker volume ls -q | grep netbird)
./setup.sh # Re-run initial setup
Note: This will reset all NetBird data.
This solution worked for: NetBird v0.45.2 + Zitadel Tested on: Ubuntu 22.04, Docker Compose
Hope this helps the community! 🚀
@hanfelt commented on GitHub (Aug 28, 2025):
Don't forget to add the User Netbird to the Application as well
@wbarnard81 commented on GitHub (Nov 19, 2025):
We use Authentik and Netbird. Updated to the latest version this morning and now I am getting this again...