
Anushiyap.76693 (Customer) asked a question.
Okta OIDC Account Selection Without Requiring Re-Authentication
Hi Okta Support,
We are integrating Okta with our application using OIDC Authorization Code flow with PKCE, and we need clarification on the behavior of the prompt parameter and Okta sessions.
Our requirement is similar to the Google account chooser experience:
- A user may have multiple accounts/sessions available.
- When they click "Login", we would like Okta to show an account-selection screen when multiple accounts are available.
- After selecting an account, the user should be authenticated using the existing Okta session for that account.
- The user should NOT be required to enter their password again every time they switch/select an account.
- If the user explicitly logs out, the corresponding Okta session should be cleared.
We currently see the following behavior:
- Without prompt, Okta can reuse the existing session, but we don't get the account-selection behavior we are looking for.
- With prompt=login, Okta shows the login flow, but this results in the user being asked for credentials again.
- prompt=none appears to perform silent authentication, but it also doesn't provide an account-selection UI.
Could you clarify:
- What are the exact supported values and behaviors of the OIDC prompt parameter in Okta?
- Is there an Okta-supported equivalent of Google's select_account behavior?
- Can Okta display an account chooser where multiple authenticated accounts/sessions can be selected without requiring password re-entry?
- If this is supported, what authorization request parameters, Okta configuration, or SDK configuration are required?
- If it is not supported for standard OIDC /authorize, is there another Okta-supported mechanism for achieving this UX?
- How does Okta manage multiple authenticated sessions/accounts in the same browser?
- Is there a recommended way for an application to switch between Okta accounts while preserving their existing Okta sessions?
- What is the recommended logout flow if we want to sign the user out of the selected Okta account/session without unnecessarily affecting other Okta sessions?
For reference, our current authorization endpoint is:
https://{okta-domain}/oauth2/default/v1/authorize
We would specifically like to understand whether there is a supported equivalent to Google's:
prompt=select_account
without using:
prompt=login
because prompt=login causes the user to authenticate again.
Kindly provide the recommended Okta configuration and OIDC request parameters for this use case, if supported.

Hi @Anushiyap.76693 (Customer) , Thank you for reaching out to the Okta Community!
This question is more appropriate for our dedicated Okta Developer Forum.
My advice would be to reach out via devforum.okta.com to take advantage of their expertise.
While we'll do our best to answer all of your questions here, this medium is more inclined towards Okta general questions around core products and features (non-custom/developer work).
Regards.
--
Help others in the community by liking or hitting Select as Best if this response helped you.
Collect them all. Learn a new skill and earn a new Okta Learning badge.
Just released: More Okta Community badges just added