User logout stage
The User Logout stage ends the user's authentik session and, if configured, initiates Single Logout.
About the user logout stage
This stage removes the current authentik session. When Single Logout is enabled for SAML or OIDC providers, authentik can also inject additional logout handling for those provider sessions.
Configuration options
This stage has no stage-specific configuration options.
Flow integration
The default flows use this stage differently:
default-invalidation-flow: used when the user logs out directly from authentik. This flow includes the User Logout stage.default-provider-invalidation-flow: the default flow used when a logout starts from an application. This flow does not include the User Logout stage.
If RP-initiated logout should also end the main authentik session, select default-invalidation-flow as the invalidation flow of the provider. For more information, see Choose the logout behavior for a provider.
Notes
When this stage runs, authentik can inject additional logout stages for active provider sessions:
- front-channel iframe logout stages
- front-channel native logout stages
- back-channel logout execution
This enables automatic provider-specific logout without manually adding those stages to the flow.