Web session logout upon OIDC access token expiration

Support intro

Sorry to hear you’re facing problems. :slightly_frowning_face:

The community help forum (help.nextcloud.com) is for home and non-enterprise users. Support is provided by other community members on a best effort / “as available” basis. All of those responding are volunteering their time to help you.

If you’re using Nextcloud in a business/critical setting, paid and SLA-based support services can be accessed via portal.nextcloud.com where Nextcloud engineers can help ensure your business keeps running smoothly.

Getting help

In order to help you as efficiently (and quickly!) as possible, please fill in as much of the below requested information as you can.

Before clicking submit: Please check if your query is already addressed via the following resources:

(Utilizing these existing resources is typically faster. It also helps reduce the load on our generous volunteers while elevating the signal to noise ratio of the forums otherwise arising from the same queries being posted repeatedly).

The Basics

  • Nextcloud Server version:
    • 34.0.4
  • Operating system and version:
    • ZimaOS 1.7.1
  • Web server and version:
    • Apache 2.4.68
  • Reverse proxy and version:
    • Caddy 2.11.4
  • PHP version:
    • 8.5.11
  • Is this the first time you’ve seen this error?:
    • Yes
  • When did this problem seem to first start?:
    • From the beginning
  • Installation method:
    • Docker Compose
  • Are you using CloudfIare, mod_security, or similar?:
    • Yes (Cloudflare DNS)

Summary of the issue you are facing:

After configuring OpenID Connect authentication with Authentik, web login works but the session terminates when the OAuth access token expires, even though the refresh token remains valid. There are no issues with the mobile app, only with the web client.

Below is a screenshot of the logs that repeats periodically upon session expiration:

Steps to replicate it:

  1. Log in with the web client using OIDC trough Authentik
  2. Wait 5 minutes for the OAuth access token validity to end
  3. Browser session is terminated and forwarding to login page

Log entries

Nextcloud

{"reqId":"i7iXLhAZOD9XEWjICL54","level":0,"time":"2026-09-28T13:52:40+00:00","remoteAddr":"192.168.1.20","user":"admin","app":"user_oidc","method":"GET","url":"/settings/admin/logging","scriptName":"/index.php","message":"The loading of lazy AppConfig values have been triggered by app \"user_oidc\"","userAgent":"Mozilla/5.0 (X11; Linux x86_64; rv:156.0) Gecko/20100101 Firefox/156.0","version":"34.0.4.1","exception":{"Exception":"RuntimeException","Message":"The loading of lazy AppConfig values have been triggered by app \"user_oidc\"","Code":0,"Trace":[{"file":"/var/www/html/lib/private/AppConfig.php","line":531,"function":"loadConfig","class":"OC\\AppConfig","type":"->","args":["user_oidc",true]},{"file":"/var/www/html/lib/private/AppConfig.php","line":395,"function":"getTypedValue","class":"OC\\AppConfig","type":"->","args":["user_oidc","store_login_token","0",true,4]},{"file":"/var/www/html/custom_apps/user_oidc/lib/Service/TokenService.php","line":131,"function":"getValueString","class":"OC\\AppConfig","type":"->","args":["user_oidc","store_login_token","0",true]},{"file":"/var/www/html/custom_apps/user_oidc/lib/AppInfo/Application.php","line":104,"function":"checkLoginToken","class":"OCA\\UserOIDC\\Service\\TokenService","type":"->","args":[]},{"file":"/var/www/html/lib/private/AppFramework/Bootstrap/FunctionInjector.php","line":26,"function":"checkLoginToken","class":"OCA\\UserOIDC\\AppInfo\\Application","type":"->","args":[{"__class__":"OCA\\UserOIDC\\Service\\TokenService","clientService":{"__class__":"OCA\\UserOIDC\\Helper\\HttpClientHelper"}}]},{"file":"/var/www/html/lib/private/AppFramework/Bootstrap/BootContext.php","line":33,"function":"injectFn","class":"OC\\AppFramework\\Bootstrap\\FunctionInjector","type":"->","args":[{"__class__":"Closure"}]},{"file":"/var/www/html/custom_apps/user_oidc/lib/AppInfo/Application.php","line":87,"function":"injectFn","class":"OC\\AppFramework\\Bootstrap\\BootContext","type":"->","args":[{"__class__":"Closure"}]},{"file":"/var/www/html/lib/private/AppFramework/Bootstrap/Coordinator.php","line":167,"function":"boot","class":"OCA\\UserOIDC\\AppInfo\\Application","type":"->","args":[{"__class__":"OC\\AppFramework\\Bootstrap\\BootContext"}]},{"file":"/var/www/html/lib/private/App/AppManager.php","line":497,"function":"bootApp","class":"OC\\AppFramework\\Bootstrap\\Coordinator","type":"->","args":["user_oidc"]},{"file":"/var/www/html/lib/private/App/AppManager.php","line":290,"function":"loadApp","class":"OC\\App\\AppManager","type":"->","args":["user_oidc"]},{"file":"/var/www/html/lib/base.php","line":1120,"function":"loadApps","class":"OC\\App\\AppManager","type":"->","args":[["authentication"]]},{"file":"/var/www/html/index.php","line":25,"function":"handleRequest","class":"OC","type":"::","args":[]}],"File":"/var/www/html/lib/private/AppConfig.php","Line":1392,"message":"The loading of lazy AppConfig values have been triggered by app \"user_oidc\"","exception":"{\"class\":\"RuntimeException\",\"message\":\"The loading of lazy AppConfig values have been triggered by app \\\"user_oidc\\\"\",\"code\":0,\"file\":\"/var/www/html/lib/private/AppConfig.php:1392\",\"trace\":\"#0 /var/www/html/lib/private/AppConfig.php(531): OC\\AppConfig->loadConfig('user_oidc', true)\\n#1 /var/www/html/lib/private/AppConfig.php(395): OC\\AppConfig->getTypedValue('user_oidc', 'store_login_tok...', '0', true, 4)\\n#2 /var/www/html/custom_apps/user_oidc/lib/Service/TokenService.php(131): OC\\AppConfig->getValueString('user_oidc', 'store_login_tok...', '0', true)\\n#3 /var/www/html/custom_apps/user_oidc/lib/AppInfo/Application.php(104): OCA\\UserOIDC\\Service\\TokenService->checkLoginToken()\\n#4 /var/www/html/lib/private/AppFramework/Bootstrap/FunctionInjector.php(26): OCA\\UserOIDC\\AppInfo\\Application->checkLoginToken(Object(OCA\\UserOIDC\\Service\\TokenService))\\n#5 /var/www/html/lib/private/AppFramework/Bootstrap/BootContext.php(33): OC\\AppFramework\\Bootstrap\\FunctionInjector->injectFn(Object(Closure))\\n#6 /var/www/html/custom_apps/user_oidc/lib/AppInfo/Application.php(87): OC\\AppFramework\\Bootstrap\\BootContext->injectFn(Object(Closure))\\n#7 /var/www/html/lib/private/AppFramework/Bootstrap/Coordinator.php(167): OCA\\UserOIDC\\AppInfo\\Application->boot(Object(OC\\AppFramework\\Bootstrap\\BootContext))\\n#8 /var/www/html/lib/private/App/AppManager.php(497): OC\\AppFramework\\Bootstrap\\Coordinator->bootApp('user_oidc')\\n#9 /var/www/html/lib/private/App/AppManager.php(290): OC\\App\\AppManager->loadApp('user_oidc')\\n#10 /var/www/html/lib/base.php(1120): OC\\App\\AppManager->loadApps(Array)\\n#11 /var/www/html/index.php(25): OC::handleRequest()\\n#12 {main}\"}","CustomMessage":"The loading of lazy AppConfig values have been triggered by app \"user_oidc\""},"id":"6aba71293ede7"}

{"reqId":"i7iXLhAZOD9XEWjICL54","level":0,"time":"2026-09-28T13:52:40+00:00","remoteAddr":"192.168.1.20","user":"admin","app":"user_oidc","method":"GET","url":"/settings/admin/logging","scriptName":"/index.php","message":"[TokenService] checkLoginToken: store_login_token is enabled","userAgent":"Mozilla/5.0 (X11; Linux x86_64; rv:156.0) Gecko/20100101 Firefox/156.0","version":"34.0.4.1","data":{"app":"user_oidc"},"id":"6aba71293eda5"}

{"reqId":"i7iXLhAZOD9XEWjICL54","level":0,"time":"2026-09-28T13:52:40+00:00","remoteAddr":"192.168.1.20","user":"admin","app":"user_oidc","method":"GET","url":"/settings/admin/logging","scriptName":"/index.php","message":"[TokenService] checkLoginToken: we never had a token before, check not needed","userAgent":"Mozilla/5.0 (X11; Linux x86_64; rv:156.0) Gecko/20100101 Firefox/156.0","version":"34.0.4.1","data":{"app":"user_oidc"},"id":"6aba71293ed9d"}

Web Browser

[WARN] core: User session was terminated, forwarding to login page. 
Object { app: "core", uid: "d675eff1-5f27-4922-91f9-016b88f5a01e", level: 0 }
core-common.js:1:2800697

Web server / Reverse Proxy

The output of your Apache/nginx/system log in /var/log/____:


Configuration

Nextcloud

$CONFIG = array (
  'htaccess.RewriteBase' => '/',
  'memcache.local' => '\\OC\\Memcache\\APCu',
  'apps_paths' => 
  array (
    0 => 
    array (
      'path' => '/var/www/html/apps',
      'url' => '/apps',
      'writable' => false,
    ),
    1 => 
    array (
      'path' => '/var/www/html/custom_apps',
      'url' => '/custom_apps',
      'writable' => true,
    ),
  ),
  'upgrade.disable-web' => true,
  'instanceid' => 'id...',
  'passwordsalt' => 'password...',
  'secret' => 'secret...',
  'trusted_domains' => 
  array (
    0 => '192.168.1.20:10081',
    1 => 'nextcloud.domain.stream',
  ),
  'datadirectory' => '/var/www/html/data',
  'dbtype' => 'pgsql',
  'version' => '34.0.4.1',
  'overwrite.cli.url' => 'https://nextcloud.domain.stream',
  'dbname' => 'casaos',
  'dbhost' => '192.168.1.20:5432',
  'dbtableprefix' => 'oc_',
  'dbuser' => 'oc_admin',
  'dbpassword' => 'db-password...',
  'installed' => true,
  'overwriteprotocol' => 'https',
  'overwritehost' => 'nextcloud.domain.stream',
  'trusted_proxies' => 
  array (
    0 => '192.168.1.0/24',
    1 => '172.16.0.0/12',
  ),
  'mail_smtppassword' => 'smtp-password...',
  'mail_smtpname' => 'email@gmail.com',
  'mail_domain' => 'domain.stream',
  'mail_from_address' => 'nextcloud',
  'mail_smtpmode' => 'smtp',
  'mail_smtpsecure' => 'ssl',
  'mail_smtphost' => 'smtp.gmail.com',
  'mail_smtpauth' => true,
  'mail_smtpport' => '465',
  'mail_sendmailmode' => 'smtp',
  'mail_smtpstreamoptions' => 
  array (
    'ssl' => 
    array (
      'allow_self_signed' => false,
      'verify_peer' => true,
      'verify_peer_name' => true,
    ),
  ),
  'loglevel' => 0,
  'maintenance' => false,
  'maintenance_window_start' => 3,
  'app_install_overwrite' => 
  array (
  ),
  'forwarded_for_headers' => 
  array (
    0 => 'HTTP_X_FORWARDED_FOR',
  ),
  'default_phone_region' => 'IT',
);

Check offline_access and also see Nextcloud site constantly reloading due to token refresh · Issue #1449 · nextcloud/user_oidc · GitHub as a possibility.

I had already tried including offline_access, but it still didn’t work. After changing the “Refresh Token Threshold” to seconds=0, as suggested in this comment #1449, it started generating new access tokens.

UPDATE: It works while the browser is active at the time of the renewal. If the browser is closed or suspended it’s not able to automatically renew the session and redirects to the login page. I’m not sure if that’s normal because other software I connected with OAuth simply works and always keep the session active as long as it is on authentik.