OIDC Error: login_required / interaction_required / consent_required (silent authentication failed)
A silent sign-in (prompt=none, iframe or refresh) couldn’t complete because the user must interact — no session, consent needed, or third-party cookies blocked.
Seen on:
REST API
Meaning
SPAs renew tokens silently in hidden iframes. Safari ITP, Chrome third-party cookie blocking, expired IdP sessions or new consent requirements return login_required/interaction_required. Use refresh tokens with rotation or redirect for interactive login.
Common causes
- IdP session expired (user must log in)
- Third-party cookies blocked for the iframe
- New consent or MFA required (interaction_required)
- Custom domain not configured for the IdP (cross-site cookies)
⚡ Quick fix
- Fall back to an interactive redirect on these errors
- Use refresh tokens (rotating) instead of iframe renewal
- Put the IdP on a custom subdomain of your site
Detailed fix by platform
JavaScript
- javascript
try { await auth0.getTokenSilently(); } catch (e) { if (["login_required", "consent_required", "interaction_required"].includes(e.error)) await auth0.loginWithRedirect(); }
How to diagnose
- Error — Which code?
- Browser — Third-party cookies blocked?
- Session — IdP session alive?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026