Skip to content
English
  • There are no suggestions because the search field is empty.

SSO Login Not Working – Authentication Error

Quick Guide: If the Single Sign-On (SSO) login fails with the error message "Authentication error: failed to obtain access token", the cause is usually a central SSO configuration issue or an expired client secret configured with the identity provider.


First, check: Who is affected?

Choose the appropriate scenario and go to the corresponding section:

a) Only one user is affected
→ see Problem affects a single user

b) Multiple or all users are affected
→ see Problem affects multiple users


a) Problem affects a single user

If only one user is affected while others can log in via SSO, the issue is usually not caused by the central SSO configuration.

Check the following:

  • Does the user exists correctly in the Identity Provider

  • is the user assigned to the correct group or application

  • Is the user allowed to access via SSO

If the problem persists, proceed to "Problem persists below".


b) Problem affects multiple users

If multiple or all users are affected, the issue is likely with the central SSO configuration.

  1. Check login logs at the Identity Provider
    Ask your IT department to review the login logs to identify specific error messages or configuration issues.

  2. Check the Client Secret
    In many cases, the Client Secret has expired. 

    Verify:

    • Whether the Client Secret is still valid

    • If necessary, renew the Client Secret

       

An expired Client Secret completely prevents SSO login.


Problem persists?

If users still cannot log in via SSO after checking or renewing the Client Secret, contact Lemontaps Support at:

support@lemontaps.com

Please provide:

  • The Identity Provider used (e.g., Entra ID)

  • Since when the login stopped working

  • Exact error message (if available)

This helps us troubleshoot the issue quickly and accurately.


FAQs

What happens if the Client Secret expires?
Many OIDC integrations use Client Secrets with limited validity. Once expired, SSO login is no longer possible.

We no longer have access to the account – what can we do?
In this case, you can restore access using our SSO recovery process.
There, we guide you step by step on how to store a new client secret and reactivate the login.

Please follow the steps below to restore the SSO connection:

  1. Open the following link: lemontaps.com/sso-recovery
    (If you experience any issues opening the link, please try again in an incognito/private browsing window.)
  2. Enter the email address of a Team Admin.
    (Only Team Admins can receive the recovery instructions and, if necessary, forward them internally.)
  3. Follow the instructions in the email to restore the SSO connection.