<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Topics tagged with openid-connect]]></title><description><![CDATA[A list of topics that have been tagged with openid-connect]]></description><link>https://fusionauth.io/community/forum/tags/openid-connect</link><generator>RSS for Node</generator><lastBuildDate>Tue, 29 Sep 2026 00:12:40 GMT</lastBuildDate><atom:link href="https://fusionauth.io/community/forum/tags/openid-connect.rss" rel="self" type="application/rss+xml"/><pubDate>Invalid Date</pubDate><ttl>60</ttl><item><title><![CDATA[SocketTimeoutException when resolving OpenID Connect configuration for external IdP]]></title><description><![CDATA[<p dir="auto">The SocketTimeoutException: Read timed out error indicates that FusionAuth successfully initiates a connection to the external identity provider's discovery endpoint, but the provider doesn't respond within the configured timeout period. This is an intermittent connectivity issue between FusionAuth and the external provider.</p>
Investigation Steps

<strong>Check FusionAuth Event Logs</strong>: Navigate to <strong>System → Event Log</strong> to find specific instances of the timeout errors with timestamps. The <a href="https://fusionauth.io/docs/apis/event-logs" rel="nofollow ugc">Event Log</a> contains messages from asynchronous code execution, including connection errors to external services.
<strong>Verify the external endpoint</strong>: Test the discovery endpoint manually (e.g., via curl) to confirm it's responding correctly
<strong>Look for patterns</strong>: Note the times when errors occur to identify if there's a pattern
<strong>Enable debug logging</strong>: Turn on debugging in FusionAuth to get more detailed information about the OIDC connection attempts. This is a recommended first step when troubleshooting any OIDC connection issues.

Root Cause
<p dir="auto">Based on investigation, when the external provider's endpoint:</p>

DNS resolves correctly
TLS handshake completes successfully
Returns HTTP 200 with valid JSON during manual testing
But still fails intermittently from FusionAuth

<p dir="auto">This indicates the external provider may be rate-limiting, blocking, or experiencing intermittent service issues that affect automated requests from FusionAuth.</p>
Workaround
<p dir="auto">Instead of using the OpenID Connect Discovery URL, manually configure the endpoints in your FusionAuth identity provider settings. This bypasses the discovery mechanism and eliminates the timeout errors during the configuration resolution phase.</p>
<p dir="auto">To configure manual endpoints:</p>

Go to your OIDC Identity Provider configuration (<strong>Settings → Identity Providers</strong>)
Toggle <strong>Discover endpoints</strong> to Off (disabled)
Explicitly set the three required endpoints:

<strong>Authorization endpoint</strong>: https://accounts.example.com/tenant/oauth/authorize
<strong>Token endpoint</strong>: https://accounts.example.com/tenant/oauth/token
<strong>Userinfo endpoint</strong>: https://accounts.example.com/tenant/oauth/userinfo



<p dir="auto">This manual configuration approach is commonly used with providers like GitHub and Discord that don't implement standard discovery endpoints, and can also be used to work around discovery endpoint reliability issues.</p>
<p dir="auto"><strong>Note</strong>: If your external provider uses RS256 to sign tokens (rather than HS256), be aware that FusionAuth currently doesn't allow manual configuration of the JWKS URL when discovery is disabled. This may cause id_token signature verification issues. If you encounter this, you may need to continue using discovery or contact FusionAuth support for alternatives.</p>
Next Steps
<p dir="auto">Contact your external identity provider to:</p>

Report the intermittent timeout issues
Share the timeout error logs and timestamps
Ask if they're experiencing service issues or if FusionAuth's IP range needs to be whitelisted
Inquire about any rate limiting policies that might affect discovery endpoint calls

Related Documentation

<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/identity-providers/overview-oidc#create-an-openid-connect-identity-provider" rel="nofollow ugc">Add an OpenID Connect Identity Provider</a> - Complete guide to configuring OIDC IdPs
<a href="https://fusionauth.io/docs/lifecycle/authenticate-users/identity-providers/overview-oidc#troubleshooting" rel="nofollow ugc">OIDC Troubleshooting</a> - First steps for troubleshooting OIDC connections
<a href="https://fusionauth.io/docs/apis/identity-providers/openid-connect" rel="nofollow ugc">OpenID Connect API</a> - API reference for managing OIDC identity providers
<a href="https://fusionauth.io/docs/apis/event-logs" rel="nofollow ugc">Event Log API</a> - How to access and query event logs programmatically

]]></description><link>https://fusionauth.io/community/forum/topic/3157/sockettimeoutexception-when-resolving-openid-connect-configuration-for-external-idp</link><guid isPermaLink="true">https://fusionauth.io/community/forum/topic/3157/sockettimeoutexception-when-resolving-openid-connect-configuration-for-external-idp</guid><dc:creator><![CDATA[FASupportBot]]></dc:creator><pubDate>Invalid Date</pubDate></item></channel></rss>