The SocketTimeoutException: Read timed out error indicates that FusionAuth successfully initiates a connection to the external identity provider's discovery endpoint, but the provider doesn't respond within the configured timeout period. This is an intermittent connectivity issue between FusionAuth and the external provider.
Investigation Steps Check FusionAuth Event Logs: Navigate to System → Event Log to find specific instances of the timeout errors with timestamps. The Event Log contains messages from asynchronous code execution, including connection errors to external services. Verify the external endpoint: Test the discovery endpoint manually (e.g., via curl) to confirm it's responding correctly Look for patterns: Note the times when errors occur to identify if there's a pattern Enable debug logging: Turn on debugging in FusionAuth to get more detailed information about the OIDC connection attempts. This is a recommended first step when troubleshooting any OIDC connection issues. Root CauseBased on investigation, when the external provider's endpoint:
DNS resolves correctly TLS handshake completes successfully Returns HTTP 200 with valid JSON during manual testing But still fails intermittently from FusionAuthThis indicates the external provider may be rate-limiting, blocking, or experiencing intermittent service issues that affect automated requests from FusionAuth.
WorkaroundInstead of using the OpenID Connect Discovery URL, manually configure the endpoints in your FusionAuth identity provider settings. This bypasses the discovery mechanism and eliminates the timeout errors during the configuration resolution phase.
To configure manual endpoints:
Go to your OIDC Identity Provider configuration (Settings → Identity Providers) Toggle Discover endpoints to Off (disabled) Explicitly set the three required endpoints: Authorization endpoint: https://accounts.example.com/tenant/oauth/authorize Token endpoint: https://accounts.example.com/tenant/oauth/token Userinfo endpoint: https://accounts.example.com/tenant/oauth/userinfoThis manual configuration approach is commonly used with providers like GitHub and Discord that don't implement standard discovery endpoints, and can also be used to work around discovery endpoint reliability issues.
Note: If your external provider uses RS256 to sign tokens (rather than HS256), be aware that FusionAuth currently doesn't allow manual configuration of the JWKS URL when discovery is disabled. This may cause id_token signature verification issues. If you encounter this, you may need to continue using discovery or contact FusionAuth support for alternatives.
Next StepsContact your external identity provider to:
Report the intermittent timeout issues Share the timeout error logs and timestamps Ask if they're experiencing service issues or if FusionAuth's IP range needs to be whitelisted Inquire about any rate limiting policies that might affect discovery endpoint calls Related Documentation Add an OpenID Connect Identity Provider - Complete guide to configuring OIDC IdPs OIDC Troubleshooting - First steps for troubleshooting OIDC connections OpenID Connect API - API reference for managing OIDC identity providers Event Log API - How to access and query event logs programmatically