Elevated error rates on requests for OIDC federation requests to CTS
Timeline · 4 updates
- investigating Feb 17, 2026, 02:00 AM UTC
We are observing elevated client-side error rates for OIDC federation requests. This is currently affecting a small (<5) number of customers. We are currently investigating this issue, and will post updates as we have them.
- investigating Feb 17, 2026, 05:25 AM UTC
We have identified the condition causing the 400-series responses. We are debugging how JWTs in a specific format are failing strict validation.
- investigating Feb 17, 2026, 07:24 AM UTC
He have identified the cause of the issue, and are deploying a fix. In a handful of JWTs, the header of the JWT being sent to CipherStash CTS includes a non-standard parameter that has a boolean value. While this is technically allowed under the RFC, a recently applied patch for...
- resolved Feb 17, 2026, 08:12 AM UTC
We have deployed a fix, and the error rate has returned to zero. The incident is closed.