Troubleshooting
Cannot Log In
Recover from local, TOTP, session and OIDC sign-in failures.
Confirm the exact URL, email address and account status. Private browsing can exclude stale cookies. Repeated failures may trigger the process-local rate limiter; wait and avoid automated retries.
For local login, Admin can verify the account is active and reset TOTP from Team > Users after independently confirming identity. Password reset requires working SMTP and a correct Base URL.
For OIDC, compare the issuer and callback exactly, test discovery, verify TLS/time/DNS, and inspect the provider's login event. A verified-email or allowed-domain policy can reject an otherwise valid identity. Account linking is based on controlled identity records, not an assumption that matching email is always safe.
If OIDC is required, use /auth/local only when emergency access is enabled and the account is active, Admin, local-password capable, marked break-glass and passes TOTP where enabled.
