login_required 🔐 Authentication

OIDC Error: login_required / interaction_required / consent_required (silent authentication failed)

A silent sign-in (prompt=none, iframe or refresh) couldn’t complete because the user must interact — no session, consent needed, or third-party cookies blocked.

Seen on: REST API

Meaning

SPAs renew tokens silently in hidden iframes. Safari ITP, Chrome third-party cookie blocking, expired IdP sessions or new consent requirements return login_required/interaction_required. Use refresh tokens with rotation or redirect for interactive login.

Common causes

  • IdP session expired (user must log in)
  • Third-party cookies blocked for the iframe
  • New consent or MFA required (interaction_required)
  • Custom domain not configured for the IdP (cross-site cookies)

⚡ Quick fix

  1. Fall back to an interactive redirect on these errors
  2. Use refresh tokens (rotating) instead of iframe renewal
  3. Put the IdP on a custom subdomain of your site

Detailed fix by platform

JavaScript

  1. javascript
    try { await auth0.getTokenSilently(); }
    catch (e) { if (["login_required", "consent_required", "interaction_required"].includes(e.error)) await auth0.loginWithRedirect(); }

How to diagnose

  1. Error — Which code?
  2. Browser — Third-party cookies blocked?
  3. Session — IdP session alive?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.