Demo source stand-in

Re: Login bug after SSO refresh — workaround confirmed

Email · support@truepaddock.example · 2026-04-22

Indexed text

From: support@truepaddock.example
To: it-team@bigco.example
Date: 2026-04-22 14:08 UTC
Subject: Re: Login bug after SSO refresh — workaround confirmed

Thanks for the quick triage. We have confirmed the workaround works for affected users:

1. Have the user clear cookies for the app domain.
2. Sign in again via the Authentik tenant.
3. The new session JWT will carry the updated organizationId.

A permanent fix that re-issues the JWT on the next request after an Authentik refresh will ship in version 1.7. ETA is two weeks.

This only affects users who were members of an organization at the time of the Authentik refresh; new users are not affected. Please let us know if any user reports the workaround is not sufficient.

Back to demo