Passport.js: Error: Failed to serialize user into session
Passport logged a user in but there’s no serializeUser function (or it didn’t call done), so the session can’t store the user.
Seen on:
REST API
Meaning
Session-based Passport setups need passport.serializeUser and deserializeUser, and the session middleware before passport.session(). Calling done with undefined also fails.
Common causes
- serializeUser not defined
- done() not called / called with undefined id
- Middleware order wrong (session after passport)
- Using sessions when session: false was intended
⚡ Quick fix
- Define serializeUser/deserializeUser
- Order: express-session → passport.initialize() → passport.session()
- Use { session: false } for token-based APIs
Detailed fix by platform
JavaScript
- javascript
passport.serializeUser((user, done) => done(null, user.id)); passport.deserializeUser(async (id, done) => done(null, await User.findById(id)));
How to diagnose
- Functions — Defined?
- Middleware — Order
- Mode — Sessions or JWT?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- ExpiredToken AWS: ExpiredToken — The security token included in the request is expired
- Illegal arguments: undefined, string bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required
- invalid csrf token ForbiddenError: invalid csrf token (EBADCSRFTOKEN)
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026