Skip to content
Discussion options

You must be logged in to vote

Hey @prefixaut

super sorry for the late reply I have been swamped with a bunch of things recently.
onto your issue:

that error is misleading, sorry: RSA-OAEP-256 isn't a signature algorithm, it's a key-encryption algorithm (JWE). It shows up because your Authentik provider is set to encrypt the ID token, not just sign it, and the plugin (like most OIDC clients) expects a signed ID token (JWS), not an encrypted one (JWE). That's why the RS*/ES*/PS* hint didn't match anything you tried - those are all signing algorithms.

The fix is in Authentik, not in a key-pair:

Admin interface → Applications → Providers → your Jellyfin provider → Edit.
Open Advanced protocol settings.
Signing Key - keep …

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@prefixaut
Comment options

@ZL154
Comment options

@ZL154
Comment options

Answer selected by prefixaut
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants