---
title: "auth_oauth_end_session: single sign-on logout"
description: "A small companion addon, independent of the connector. Odoo's OAuth login only ends the Odoo session on logout; the session at the identity provider stays, and the next sign-in logs straight back in. With an end-session URL on the provider, logging out of Odoo ends that session too."
canonical_url: "https://openepcis.io/docs/connectors/odoo/single-sign-on-logout"
last_updated: "2026-10-09T10:21:44.380Z"
---

Odoo's OAuth login (`auth_oauth`) only ends the Odoo session on logout. The session at the identity provider stays, so the next *Sign in with …* logs straight back in as the same user, without asking. On a shared terminal that is the wrong behaviour, and it is the one every Odoo behind Keycloak has by default.

<table>
<thead>
  <tr>
    <th>
      
    </th>
    
    <th>
      
    </th>
  </tr>
</thead>

<tbody>
  <tr>
    <td>
      <strong>
        Module
      </strong>
    </td>
    
    <td>
      <code>
        auth_oauth_end_session
      </code>
    </td>
  </tr>
  
  <tr>
    <td>
      <strong>
        Depends on
      </strong>
    </td>
    
    <td>
      <code>
        auth_oauth
      </code>
      
       — not on the connector
    </td>
  </tr>
  
  <tr>
    <td>
      <strong>
        Installs
      </strong>
    </td>
    
    <td>
      By hand
    </td>
  </tr>
  
  <tr>
    <td>
      <strong>
        Affects
      </strong>
    </td>
    
    <td>
      Users who signed in through a provider with an end-session URL. Password logins are untouched
    </td>
  </tr>
  
  <tr>
    <td>
      <strong>
        Source
      </strong>
    </td>
    
    <td>
      <a href="https://github.com/openepcis/openepcis-odoo/tree/18.0/auth_oauth_end_session" rel="nofollow">
        openepcis-odoo
      </a>
      
       · LGPL-3
    </td>
  </tr>
</tbody>
</table>

It ships in the connector's repository because an Odoo that talks to OpenEPCIS is usually an Odoo whose users sign in through the same Keycloak, but nothing in it knows about OpenEPCIS. It is useful on its own.

## Setting it up

1. Install `auth_oauth_end_session`.
2. On the OAuth provider in Odoo — **Settings → Users & Companies → OAuth Providers** — fill in **End session URL**. For Keycloak it is the realm's OpenID Connect logout endpoint:```text
https://<host>/realms/<realm>/protocol/openid-connect/logout
```
3. On the client in Keycloak, register the Odoo login page as a valid post-logout redirect URI:```text
https://<odoo>/web/login
```

Logging out of Odoo then sends a user who signed in through that provider on to the end-session endpoint — OpenID Connect RP-initiated logout — and the provider returns them to Odoo's login page.

## One thing to expect

Odoo's OAuth login uses the implicit flow and receives no ID token, so the logout request carries no `id_token_hint`. Without it, the provider may ask the user to confirm the logout rather than ending the session silently. That is the provider being careful with a request it cannot fully attribute, not a fault in the setup.
