# Multiple IDENTITY\_PROVIDER\_FIRST\_LOGIN at the same time for the same user preventing user from signing in

**URL:** <https://forum.keycloak.org/t/multiple-identity-provider-first-login-at-the-same-time-for-the-same-user-preventing-user-from-signing-in/29582>\
**Category:** Miscellanaeous\
**Tags:** authentication, identity-brokering\
**Created:** [February 13, 2025, 2:13am UTC](https://forum.keycloak.org/t/multiple-identity-provider-first-login-at-the-same-time-for-the-same-user-preventing-user-from-signing-in/29582 "2025-02-13T02:13:21Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![clydeespeno](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/clydeespeno/32/11974_2.png) [@clydeespeno](https://forum.keycloak.org/u/clydeespeno)\
**Post date:** [February 13, 2025, 2:13am UTC](https://forum.keycloak.org/t/multiple-identity-provider-first-login-at-the-same-time-for-the-same-user-preventing-user-from-signing-in/29582/1 "2025-02-13T02:13:21Z")

</div>

Hello Everyone,

We were facing an issue with keycloak, where sporadically, a user which logs in the first time over an external IDP fails to login.

**Our Setup**

- keycloak v26.0.x, deployed as a statefulset (with 3 instances) in kubernetes
- exposed externally via cloudflare tunnel
- external IDP is Google
- cache: ispn, kubernetes

**Behaviour**

- User logs in the first time via google
- After a while, the user will be redirected to /realms//login-actions/first-broker-login
- However, it will show `Account Already Exists`. But since the user does not have a password, the IDP link could not be established.

**Browser Network Activity**

- None of the requests were seemingly duplicated or retried

**What I noticed from the event logs:**

- Multiple `IDENTITY_PROVIDER_FIRST_LOGIN` are sent for the same user (around the same time, differing only with a few hundred ms)
- All `IDENTITY_PROVIDER_FIRST_LOGIN` had different `code_id`
- Some `IDENTITY_PROVIDER_FIRST_LOGIN` will have a subsequent `IDENTITY_PROVIDER_FIRST_LOGIN_ERROR` (the pair have the same `code_id`), but not all.
- The user entity is still created in keycloak, without any IDP links and credential

**From the server logs**

- All 3 servers, with a few hundred ms difference processed the same request

Can anyone help me get insights on why this happens, and if there are any configurations that would prevent this from happening?

---

<div class="post-metadata">

**Author:** ![thodoroaba](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/thodoroaba/32/12484_2.png) [@thodoroaba](https://forum.keycloak.org/u/thodoroaba)\
**Post date:** [February 23, 2026, 9:05am UTC](https://forum.keycloak.org/t/multiple-identity-provider-first-login-at-the-same-time-for-the-same-user-preventing-user-from-signing-in/29582/2 "2026-02-23T09:05:54Z")

</div>

I also experience a similar behavior, Entra ID connected as external IDP. Multiple `IDENTITY_PROVIDER_FIRST_LOGIN ` events, infinite loop.

---

<div class="post-metadata">

**Author:** ![robson90](https://yyz2.discourse-cdn.com/free1/user_avatar/forum.keycloak.org/robson90/32/12479_2.png) [@robson90](https://forum.keycloak.org/u/robson90)\
**Post date:** [February 23, 2026, 11:36am UTC](https://forum.keycloak.org/t/multiple-identity-provider-first-login-at-the-same-time-for-the-same-user-preventing-user-from-signing-in/29582/3 "2026-02-23T11:36:59Z")

</div>

Hey @clydeespeno , have you checked if ur cache settings are correct ?

Which chart are you using ?

Have you updated to 26.4.x? Is the problem persisting ?
