<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR00002CVQOG0A5Okta Classic EngineSingle Sign-OnAnswered2026-09-30T17:01:53.000Z2026-09-30T05:02:29.000Z2026-09-30T17:01:53.000Z

Okta OIDC Account Selection Without Requiring Re-Authentication

Hi Okta Support,

We are integrating Okta with our application using OIDC Authorization Code flow with PKCE, and we need clarification on the behavior of the prompt parameter and Okta sessions.

Our requirement is similar to the Google account chooser experience:

  1. A user may have multiple accounts/sessions available.
  2. When they click "Login", we would like Okta to show an account-selection screen when multiple accounts are available.
  3. After selecting an account, the user should be authenticated using the existing Okta session for that account.
  4. The user should NOT be required to enter their password again every time they switch/select an account.
  5. If the user explicitly logs out, the corresponding Okta session should be cleared.

We currently see the following behavior:

  • Without prompt, Okta can reuse the existing session, but we don't get the account-selection behavior we are looking for.
  • With prompt=login, Okta shows the login flow, but this results in the user being asked for credentials again.
  • prompt=none appears to perform silent authentication, but it also doesn't provide an account-selection UI.

Could you clarify:

  1. What are the exact supported values and behaviors of the OIDC prompt parameter in Okta?
  2. Is there an Okta-supported equivalent of Google's select_account behavior?
  3. Can Okta display an account chooser where multiple authenticated accounts/sessions can be selected without requiring password re-entry?
  4. If this is supported, what authorization request parameters, Okta configuration, or SDK configuration are required?
  5. If it is not supported for standard OIDC /authorize, is there another Okta-supported mechanism for achieving this UX?
  6. How does Okta manage multiple authenticated sessions/accounts in the same browser?
  7. Is there a recommended way for an application to switch between Okta accounts while preserving their existing Okta sessions?
  8. What is the recommended logout flow if we want to sign the user out of the selected Okta account/session without unnecessarily affecting other Okta sessions?

For reference, our current authorization endpoint is:

https://{okta-domain}/oauth2/default/v1/authorize

We would specifically like to understand whether there is a supported equivalent to Google's:

prompt=select_account

without using:

prompt=login

because prompt=login causes the user to authenticate again.

Kindly provide the recommended Okta configuration and OIDC request parameters for this use case, if supported.


Loading
Okta OIDC Account Selection Without Requiring Re-Authentication