I can't log in
The shortest path on your own machine is one button. Every other provider is still there if you have configured it. Nothing on this page turns the local bypass on for a public URL.
1. Local tryout, no OAuth app
This is the default for a first self-host. Compose and frontend/.env.example set DEV_AUTH_BYPASS=true. The button Continue on this machine is shown only when that flag is true and NEXTAUTH_URL (or NEXT_PUBLIC_APP_URL) is localhost, or the web process is running in development. It signs you in as the local dev user and sends you to onboarding.
cp .env.example .env
cp frontend/.env.example frontend/.env
npm run compose:upThen open http://localhost:3000 and use Continue on this machine. For npm run dev without Compose, the web process reads frontend/.env, not the root file.
If the button is missing, the flag is off or the site URL is not local while NODE_ENV is production. Do not set DEV_AUTH_BYPASS=true on a hostname other people can reach. The API refuses to start in that case.
2. GitHub, GitLab, or Google
NEXTAUTH_URL must be the exact origin in the address bar, including http versus https. Register the callback that matches it:
- GitHub:
{NEXTAUTH_URL}/api/auth/callback/githuband setGITHUB_CLIENT_ID,GITHUB_CLIENT_SECRET,NEXT_PUBLIC_GITHUB_OAUTH=true - Google:
{NEXTAUTH_URL}/api/auth/callback/googleand setGOOGLE_CLIENT_ID,GOOGLE_CLIENT_SECRET - GitLab:
{NEXTAUTH_URL}/api/auth/callback/gitlaband setGITLAB_CLIENT_ID,GITLAB_CLIENT_SECRET
Under Compose, only the GitHub client id and secret are passed into the web container. Google and GitLab client credentials are passed to the api container, not to web, so those two buttons do not appear until the web service receives them. See the self-host page.
3. Company SSO
On the start page, choose Work SSO and enter your work email. That calls /api/auth/sso/discover, then /api/auth/sso/start. SSO stays available. It needs an org SSO config (or SSO_ENABLED on the API). A domain with no config returns “No SSO configured for that email domain”.
4. Still stuck
- After a secret change, recreate containers with
npm run compose:upso web and api both see the newNEXTAUTH_SECRET. - A “State cookie was missing” error means
NEXTAUTH_URLdoes not match the URL you opened. - Signed-out landing uses
/?signedOut=1so an old session does not immediately send you to onboarding.