Skip to main content
agrillea
New Member
March 10, 2025
Question

Problem logout using Fortiauthenticator OAUTH2 service

  • March 10, 2025
  • 7 replies
  • 1578 views

Good morning, I urgently need help.
In one of my web applications I implemented oauth2 authentication using the OAUTH2 service present in FortiAuthenticator v6.6.1  via REST API, so I configured a confidential type relying party, openid type scope and some claims. The entire OAuth2 flow works well in the sense that I authenticate myself and the token is released to me but I would like to know how to log out. The log out is not documented in the documentation. I would like to know how to log out and have the cookie deleted with some command. The only way I get this effect is to delete the server history. Is there a way to do it or is it not provided??? Thanks in advance

7 replies

Jean-Philippe_P
Staff & Editor
Staff & Editor
March 12, 2025

Hello agrillea, 

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

 

Thanks, 

Jean-Philippe - Fortinet Community Team
Jean-Philippe_P
Staff & Editor
Staff & Editor
March 13, 2025

Hello,

 

We are still looking for an answer to your question.

 

We will come back to you ASAP.

 

Thanks,

Jean-Philippe - Fortinet Community Team
agrillea
agrilleaAuthor
New Member
March 13, 2025

Maybe I found the solution but I wanted to have confirmation from you. In practice to log out via the rest api I first revoke the token and then log in again. This way it seems to work....but since it is not documented I wanted to know if it was correct. Thanks

Markus_M
Staff & Editor
Staff & Editor
March 14, 2025

Hi agrillea,

 

I think the method you have there, is good. The oauth logout endpoint on the API seems to not exist. What might help in addition (not answering your question) is the token expiry timer which by default sits at 10h. If you have automated accesses only, you could potentially work with lower timers, like 5 minutes or so.

 

Best regards,

 

Markus

agrillea
agrilleaAuthor
New Member
October 9, 2025

We are currently working with a client using FortiAuthenticator v6.6.1, and we've encountered some challenges in integrating their web applications with our internal OIDC/OAuth2 service. Specifically, this version does not provide a dedicated API for logging out users. As a workaround, we have been using the revoke_token API to invalidate the session, and then attempting to force a re-authentication via an iframe.

However, we've noticed that even after performing these actions, the user session often remains active, and users are sometimes able to re-enter the system without completing the full login process. This behavior seems to suggest that the session is not being fully terminated, despite the token being revoked.

Given these challenges, we are considering an upgrade to a more recent version of FortiAuthenticator. We would appreciate any insights or recommendations regarding whether this issue has been addressed in later releases, or if there are any best practices that could help us ensure proper session termination and logout functionality in v6.6.1.

Thank you for your time and support. We look forward to your feedback.

Best regards,

Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Virtual event | September 2026. SASE summit. The age of autonomous trust. Register here!