Skip to content

error: ErrorController => error Unknown authentication strategy "openid" when using OIDC #10235

Description

@mescaja

Deployed LibreChat latest version on to Kubernetes. Set OIDC in the .env file as per below (Keycloak as authorization server also deployed to Kubernetes) and created the secret librechat-credentials-env from the .env file

# OpenID
OPENID_ENABLED=true
OPENID_CLIENT_ID=LibreChat
OPENID_CLIENT_SECRET=dXx6xmssj0KEjPoSL5bvRvhDjNAiNzSr
OPENID_ISSUER=https://keycloak.poc/realms/wanaku
OPENID_SESSION_SECRET=9400e2b0fda50be8dc9e12c6281b1cc6
OPENID_SCOPE="openid profile email"
OPENID_CALLBACK_URL=/oauth/openid/callback
OPENID_REQUIRED_ROLE=librechat-role
OPENID_REQUIRED_ROLE_TOKEN_KIND=access
OPENID_REQUIRED_ROLE_PARAMETER_PATH=resource_access.LibreChat.roles
# Set to determine which user info property returned from OpenID Provider to store as the User's username
OPENID_USERNAME_CLAIM=email
# Set to determine which user info property returned from OpenID Provider to store as the User's name
OPENID_NAME_CLAIM=name
# Optional audience parameter for OpenID authorization requests
OPENID_AUDIENCE=wanaku-mcp-client

OPENID_BUTTON_LABEL=
OPENID_IMAGE_URL=
# Set to true to automatically redirect to the OpenID provider when a user visits the login page
# This will bypass the login form completely for users, only use this if OpenID is your only authentication method
OPENID_AUTO_REDIRECT=false
# Set to true to use PKCE (Proof Key for Code Exchange) for OpenID authentication
OPENID_USE_PKCE=false
#Set to true to reuse openid tokens for authentication management instead of using the mongodb session and the custom refresh token.
OPENID_REUSE_TOKENS=false
#By default, signing key verification results are cached in order to prevent excessive HTTP requests to the JWKS endpoint.
#If a signing key matching the kid is found, this will be cached and the next time this kid is requested the signing key will be served from the cache.
#Default is true.
OPENID_JWKS_URL_CACHE_ENABLED=
OPENID_JWKS_URL_CACHE_TIME= # 600000 ms eq to 10 minutes leave empty to disable caching
#Set to true to trigger token exchange flow to acquire access token for the userinfo endpoint.
OPENID_ON_BEHALF_FLOW_FOR_USERINFO_REQUIRED=
OPENID_ON_BEHALF_FLOW_USERINFO_SCOPE="user.read" # example for Scope Needed for Microsoft Graph API
# Set to true to use the OpenID Connect end session endpoint for logout
OPENID_USE_END_SESSION_ENDPOINT=true

Open LibreChat https://librechat.poc, login page comes up, Click on "Continue with OpenID", browser gets redirected to "https://librechat.poc/oauth/openid"

in the server log, i can see this

2025-10-23 07:46:09 warn: RAG API is either not running or not reachable at undefined, you may experience errors with file uploads.
2025-10-23 07:46:09 info: Turnstile is DISABLED (no siteKey provided).
2025-10-23 07:46:09 info: 
Outdated Config version: 1.2.1
Latest version: 1.3.0
      Check out the Config changelogs for the latest options and features added.
      https://www.librechat.ai/changelog
2025-10-23 07:46:09 info: No changes needed for 'USER' role permissions
2025-10-23 07:46:09 info: No changes needed for 'ADMIN' role permissions
2025-10-23 07:46:09 info: Configuring social logins...
2025-10-23 07:46:09 info: Configuring OpenID Connect...
2025-10-23 07:46:09 info: [indexSync] Messages are fully synced: 23/23
2025-10-23 07:46:09 info: [indexSync] Conversations are fully synced: 2/2
2025-10-23 07:46:14 error: [openidStrategy] Fetch error: fetch failed
2025-10-23 07:46:14 error: [openidStrategy] fetch failed
2025-10-23 07:46:14 error: OpenID Connect configuration failed - strategy not registered.
2025-10-23 07:46:14 info: Server listening on all interfaces at port 3080. Use http://localhost:3080 to access it
2025-10-23 07:46:14 info: [MCP][WanakuMCPstreamable] -------------------------------------------------┐
2025-10-23 07:46:14 info: [MCP][WanakuMCPstreamable] URL: http://wanaku-mcp-backend.wanaku.svc.cluster.local:8080/mcp
2025-10-23 07:46:14 info: [MCP][WanakuMCPstreamable] OAuth Required: true
2025-10-23 07:46:14 info: [MCP][WanakuMCPstreamable] Capabilities: undefined
2025-10-23 07:46:14 info: [MCP][WanakuMCPstreamable] Tools: undefined
2025-10-23 07:46:14 info: [MCP][WanakuMCPstreamable] Server Instructions: undefined
2025-10-23 07:46:14 info: [MCP][WanakuMCPstreamable] -------------------------------------------------┘
2025-10-23 07:46:14 info: MCP servers initialized successfully. Added 0 MCP tools.
2025-10-23 07:46:14 info: OAuth reconnect manager initialized successfully.
**2025-10-23 07:46:39 error: ErrorController => error Unknown authentication strategy "openid"**

I have seen other tickets in the past reporting similar issues using OIDC in LibreChat which seems to have been fixed. In my test scenario above, i can't work out what it's causing it.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions