immich-app/immich · error
Unable to register / . User does not exist and auto…
Error message
Unable to register ${profile.sub}/${normalizedEmail || '(no email)'}. User does not exist and auto registering is disabled. To enable set OAuth Auto Register to true in admin settings. What it means
In the OAuth callback, if no existing user matches the OAuth profile and auto-registration is disabled in admin settings, the server refuses to create an account: it logs this warning (including the OAuth subject and normalized email) and throws BadRequestException('OAuth authentication failed'). The user cannot sign in via OAuth until an account exists or auto-register is enabled.
Solutions
- Enable 'OAuth Auto Register' in Administration > Settings > OAuth authentication.
- Create the user account first (admin Users page) with matching email, then log in via OAuth.
- Check the OAuth profile's email claim matches an existing user's email.
- If the email legitimately changed, update the user's email in admin settings.
Defensive patterns
Strategy: validation
Validate before calling
// before enabling OAuth login, ensure every expected IdP email has a server account
const emails = await idp.listEmails();
for (const email of emails) {
if (!(await server.userExistsByEmail(email))) console.warn(`No account for ${email}; enable auto-register or create it`);
} Try / catch
try {
await api.oauthCallback(url);
} catch (e) {
if (e instanceof BadRequestException && e.message.includes('OAuth authentication failed')) {
showToast('No account exists for this OAuth identity and auto-register is disabled');
} else throw e;
} Prevention
- Enable OAuth Auto Register if any IdP user should get an account on first login.
- Pre-provision accounts with emails matching the IdP's email claim.
- Keep IdP emails in sync with server account emails (watch for email changes).
- Test OAuth with the real account before rolling out to users.
When it happens
Trigger: OAuth login/callback where getByOAuthId/getByEmail find no user and the autoRegister setting is false.
Common situations: Fresh OAuth login from a brand-new email on a server with OAuth Auto Register off; email changed at the IdP so it no longer matches; testing OAuth with a different account; migration where users were never provisioned.
Related errors
- OAuth login failed
- Password login has been disabled
- authToken is required
- Device ' ' does not exist. If using Docker, make sure this…
- Error backchannel logout: token validation failed
AI-assisted analysis of immich-app/immich@f48d4b3321 (2026-09-15).
Data as JSON: /api/errors/35560f623cfca4ab.
Report an issue: GitHub.
Appendix: source
Thrown at server/src/services/auth.service.ts:338
if (emailUser.oauthId) {
this.logger.debug('OAuth login conflict: email already linked to different account');
throw new BadRequestException('OAuth authentication failed');
}
user = await this.userRepository.update(emailUser.id, { oauthId: profile.sub });
}
}
const role = this.getRoleClaim(profile, roleClaim);
const isAdmin = role === 'admin';
if (user && role && isAdmin !== user.isAdmin) {
user = await this.userRepository.update(user.id, { isAdmin });
}
// register new user
if (!user) {
if (!autoRegister) {
this.logger.warn(
`Unable to register ${profile.sub}/${normalizedEmail || '(no email)'}. User does not exist and auto registering is disabled. To enable set OAuth Auto Register to true in admin settings.`,
);
throw new BadRequestException('OAuth authentication failed');
}
if (!normalizedEmail) {
throw new BadRequestException('OAuth profile does not have an email address');
}
this.logger.log(`Registering new user: ${profile.sub}/${normalizedEmail}`);
const storageLabel = this.getClaim(profile, {
key: storageLabelClaim,
default: '',
isValid: (value: unknown): value is string => typeof value === 'string',
});
const storageQuota = this.getClaim(profile, {
key: storageQuotaClaim,View on GitHub (pinned to f48d4b3321)