|
I'm trying to setup SSO/OIDC with Authentik for my Jellyfin, and I can't for the live of me get this to work. I'm very much confused, as any RSA should work I would assume (or at least the warning lets me to believe with Jellyfin Version: Of course, searched for it and found it in the FAQ: However, creating a new Key-Pair via Authentik, or creating one manually and importing it, doesn't resolve the issue. Full Log when attempting to login: I have also checked the Issue #95 , which was mentioned in the logs, but that seems not to be relevant for now. Jellyfin as well as Authentik are running in Docker containers, behind a Caddy instance. Here's also the config export, with the secrets and IPs redacted: {
"FormatVersion": 1,
"ExportedAt": "2026-08-21T20:43:03.0913638Z",
"PluginVersion": "2.5.22.0",
"Encrypted": false,
"Payload": {
"Configuration": {
"Enabled": true,
"BlockEmptyPasswordLogin": true,
"RequireChallengeIpMatch": false,
"RegisteredDeviceMaxAgeDays": 0,
"BareDeviceIdBypassEnabled": false,
"RequireForAllUsers": false,
"RequireTwoFactorToDisable": true,
"SelfServiceStepUpMode": 2,
"StepUpLevel": 0,
"StepUpWindowSeconds": 300,
"AllowIndefiniteTrust": false,
"HideBuiltInTwoFactorButton": true,
"HideBuiltInPasskeyButton": true,
"EnforcementScope": 0,
"LanBypassEnabled": false,
"LanBypassCidrs": [],
"TrustForwardedFor": true,
"TrustedProxyCidrs": [
"censored"
],
"EmailOtpEnabled": false,
"HibpEnabled": false,
"EmailOtpTtlSeconds": 300,
"ChallengeTokenTtlSeconds": 300,
"PairingCodeTtlSeconds": 300,
"MaxFailedAttempts": 5,
"LockoutDurationMinutes": 15,
"ExemptAdministratorsFromLockout": true,
"DisablePasswordLogin": false,
"AllowAdminPasswordLogin": true,
"AllowPasswordLoginOnLan": true,
"PasswordLoginExemptCidrs": [],
"EnablePasswordRecovery": false,
"HideBuiltInForgotPassword": true,
"LoginLinksBelowQuickConnect": false,
"AuditLogMaxEntries": 1000,
"NtfyUrl": "",
"NtfyTopic": "",
"NtfyToken": "",
"NtfyUsername": "",
"NtfyPassword": "",
"GotifyUrl": "",
"GotifyAppToken": "",
"AllowPrivateNotificationTargets": false,
"NotifyEmailAddresses": [],
"SmtpHost": "",
"SmtpPort": 587,
"SmtpUseSsl": true,
"SmtpUsername": "",
"SmtpPassword": "",
"SmtpFromAddress": "",
"SmtpFromName": "Jellyfin 2FA",
"UserEmails": [],
"TotpIssuerName": "Jellyfin",
"DefaultLanguage": "en",
"PreVerifyWindowSeconds": 120,
"TrustCookieTtlDays": 30,
"NatHairpinSelfIpBypass": false,
"DefaultMaxConcurrentSessions": 0,
"EnrollmentDeadline": null,
"WebhookUrl": "",
"WebhookSecret": "",
"WebhookHeaders": [],
"GeoIpAsnDbPath": "",
"GeoIpCountryDbPath": "",
"WebAuthnRpId": "",
"WebAuthnOrigins": [],
"BypassForExternalAuthProviders": true,
"OidcProviders": [
{
"Id": "authentik",
"DisplayName": "Authentik",
"Preset": "authentik",
"DiscoveryUrl": "https://auth.yggdrasil.internal/application/o/jellyfin/.well-known/openid-configuration",
"ClientId": "censored",
"ClientSecret": "",
"Scopes": "openid profile email",
"AcrValues": "",
"UsernameClaim": "preferred_username",
"AllowedGroups": "",
"AdminGroups": "",
"AllowAdminGroupElevation": false,
"TemplateUserId": "",
"AutoCreateUsers": true,
"LinkExistingUsersByUsername": true,
"RequireIdpMfa": false,
"BypassPluginTwoFa": true,
"Enabled": true,
"ShowLoginButton": true,
"ForceHttps": false,
"AllowPrivateNetworks": true,
"AdditionalAllowedCidrs": "censored",
"SyncProfilePicture": false,
"PictureClaim": "picture",
"PromptSelectAccount": false,
"OmitPromptLogin": false,
"ApplyRoleLibraryAccess": false,
"RoleLibraryMappings": [],
"EmailClaim": "email",
"SyncEmailFromClaim": true,
"ButtonText": "Sign in with Authentik",
"ButtonIconUrl": "",
"ForcePasswordSetup": false,
"RpInitiatedLogoutEnabled": false,
"RpInitiatedLogoutRedirectUri": "",
"CreatedAt": "2026-08-21T16:40:05.0415017Z"
}
],
"GeoIpCityDbPath": "",
"IpBanEnabled": false,
"IpBanFailureThreshold": 10,
"IpBanFailureWindowMinutes": 10,
"IpBanDurationHours": 24,
"IpBanExemptCidrs": [],
"ImpossibleTravelEnabled": false,
"ImpossibleTravelMaxKmh": 900,
"WebhookEd25519PrivateKey": "",
"OnboardingPasswordMinLength": 16,
"OnboardingPasswordRequireUppercase": false,
"OnboardingPasswordRequireLowercase": false,
"OnboardingPasswordRequireDigit": false,
"OnboardingPasswordRequireSymbol": false
},
"RedactedFields": [
"OidcProviders[0].ClientSecret"
]
}
} |
Replies: 1 comment 3 replies
|
Hey @prefixaut super sorry for the late reply I have been swamped with a bunch of things recently. that error is misleading, sorry: RSA-OAEP-256 isn't a signature algorithm, it's a key-encryption algorithm (JWE). It shows up because your Authentik provider is set to encrypt the ID token, not just sign it, and the plugin (like most OIDC clients) expects a signed ID token (JWS), not an encrypted one (JWE). That's why the RS*/ES*/PS* hint didn't match anything you tried - those are all signing algorithms. The fix is in Authentik, not in a key-pair: Admin interface → Applications → Providers → your Jellyfin provider → Edit. If clearing the Encryption Key fixes it (it should), let me know and I'll add this exact case to the Troubleshooting page so the next person finds it faster. On v2.6.0 (just released) the verification-failure message also spells out the specific cause, though I should extend it to name this "that's an encryption algorithm, not a signing one" case explicitly. Lmk if that fixes all the issues and again sorry for the late reply |
Hey @prefixaut
super sorry for the late reply I have been swamped with a bunch of things recently.
onto your issue:
that error is misleading, sorry: RSA-OAEP-256 isn't a signature algorithm, it's a key-encryption algorithm (JWE). It shows up because your Authentik provider is set to encrypt the ID token, not just sign it, and the plugin (like most OIDC clients) expects a signed ID token (JWS), not an encrypted one (JWE). That's why the RS*/ES*/PS* hint didn't match anything you tried - those are all signing algorithms.
The fix is in Authentik, not in a key-pair:
Admin interface → Applications → Providers → your Jellyfin provider → Edit.
Open Advanced protocol settings.
Signing Key - keep …