immich-app/immich · error

Unable to register / . User does not exist and auto…

Error message

Unable to register ${profile.sub}/${normalizedEmail || '(no email)'}. User does not exist and auto registering is disabled. To enable set OAuth Auto Register to true in admin settings.

What it means

In the OAuth callback, if no existing user matches the OAuth profile and auto-registration is disabled in admin settings, the server refuses to create an account: it logs this warning (including the OAuth subject and normalized email) and throws BadRequestException('OAuth authentication failed'). The user cannot sign in via OAuth until an account exists or auto-register is enabled.

Solutions

  1. Enable 'OAuth Auto Register' in Administration > Settings > OAuth authentication.
  2. Create the user account first (admin Users page) with matching email, then log in via OAuth.
  3. Check the OAuth profile's email claim matches an existing user's email.
  4. If the email legitimately changed, update the user's email in admin settings.
Defensive patterns

Strategy: validation

Validate before calling

// before enabling OAuth login, ensure every expected IdP email has a server account
const emails = await idp.listEmails();
for (const email of emails) {
  if (!(await server.userExistsByEmail(email))) console.warn(`No account for ${email}; enable auto-register or create it`);
}

Try / catch

try {
  await api.oauthCallback(url);
} catch (e) {
  if (e instanceof BadRequestException && e.message.includes('OAuth authentication failed')) {
    showToast('No account exists for this OAuth identity and auto-register is disabled');
  } else throw e;
}

Prevention

When it happens

Trigger: OAuth login/callback where getByOAuthId/getByEmail find no user and the autoRegister setting is false.

Common situations: Fresh OAuth login from a brand-new email on a server with OAuth Auto Register off; email changed at the IdP so it no longer matches; testing OAuth with a different account; migration where users were never provisioned.

Related errors


AI-assisted analysis of immich-app/immich@f48d4b3321 (2026-09-15). Data as JSON: /api/errors/35560f623cfca4ab. Report an issue: GitHub.

Appendix: source

Thrown at server/src/services/auth.service.ts:338

        if (emailUser.oauthId) {
          this.logger.debug('OAuth login conflict: email already linked to different account');
          throw new BadRequestException('OAuth authentication failed');
        }
        user = await this.userRepository.update(emailUser.id, { oauthId: profile.sub });
      }
    }

    const role = this.getRoleClaim(profile, roleClaim);
    const isAdmin = role === 'admin';

    if (user && role && isAdmin !== user.isAdmin) {
      user = await this.userRepository.update(user.id, { isAdmin });
    }

    // register new user
    if (!user) {
      if (!autoRegister) {
        this.logger.warn(
          `Unable to register ${profile.sub}/${normalizedEmail || '(no email)'}. User does not exist and auto registering is disabled. To enable set OAuth Auto Register to true in admin settings.`,
        );
        throw new BadRequestException('OAuth authentication failed');
      }

      if (!normalizedEmail) {
        throw new BadRequestException('OAuth profile does not have an email address');
      }

      this.logger.log(`Registering new user: ${profile.sub}/${normalizedEmail}`);

      const storageLabel = this.getClaim(profile, {
        key: storageLabelClaim,
        default: '',
        isValid: (value: unknown): value is string => typeof value === 'string',
      });
      const storageQuota = this.getClaim(profile, {
        key: storageQuotaClaim,

View on GitHub (pinned to f48d4b3321)