# iOS/Android VPN authentications issues

**URL:** https://forum.pritunl.com/t/ios-android-vpn-authentications-issues/743
**Category:** Pritunl VPN
**Tags:** pritunl
**Created:** [February 1, 2023, 8:09pm UTC](https://forum.pritunl.com/t/ios-android-vpn-authentications-issues/743 "2023-02-01T20:09:10Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![prit-user](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/p/e47c2d/32.png) [@prit-user](https://forum.pritunl.com/u/prit-user)
#### Post date: [February 1, 2023, 8:09pm UTC](https://forum.pritunl.com/t/ios-android-vpn-authentications-issues/743/1 "2023-02-01T20:09:10Z")

</div>

I have Single Sign-On Authentication configured with Google Apps.

VPN Connections from macOS and Windows is fine but authentication is failing on iOS and Android - please advise.

Logs on the pritunl server: User auth failed “Invalid sso token”

Turning off SSO fixed the issue.

Thanks in advance

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [February 2, 2023, 4:03am UTC](https://forum.pritunl.com/t/ios-android-vpn-authentications-issues/743/2 "2023-02-02T04:03:14Z")

</div>

The single sign-on connection authentication will only work with the Pritunl Client on Linux, macOS and Windows.

---

<div class="post-metadata">

### Author: ![prit-user](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/p/e47c2d/32.png) [@prit-user](https://forum.pritunl.com/u/prit-user)
#### Post date: [February 2, 2023, 4:48am UTC](https://forum.pritunl.com/t/ios-android-vpn-authentications-issues/743/3 "2023-02-02T04:48:35Z")

</div>

thanks, Zach.

how about YubiKey or google authenticator? do they work on mobile devices?

---

<div class="post-metadata">

### Author: ![zach](https://forum.pritunl.com/user_avatar/forum.pritunl.com/zach/32/1105_2.png) [@zach](https://forum.pritunl.com/u/zach)
#### Post date: [February 2, 2023, 5:27am UTC](https://forum.pritunl.com/t/ios-android-vpn-authentications-issues/743/4 "2023-02-02T05:27:54Z")

</div>

If single sign-on connection authentication is disabled both will work on mobile devices. Single sign-on can still be used on mobile devices just without the additional per-connection authentication. The YubiKey must be connected to the device. This will work on Android and Apple devices with USB-C, it may not work on iOS devices.

---

<div class="post-metadata">

### Author: ![gokoya9930](https://forum.pritunl.com/letter_avatar_proxy/v4/letter/g/a587f6/32.png) [@gokoya9930](https://forum.pritunl.com/u/gokoya9930)
#### Post date: [August 5, 2026, 11:38am UTC](https://forum.pritunl.com/t/ios-android-vpn-authentications-issues/743/5 "2026-08-05T11:38:08Z")

</div>

> <https://github.com/pritunl/pritunl/pull/584>
>
> Adds an opt-in \`sso\_webauth\` server option so stock OpenVPN clients (OpenVPN Con…nect, ics-openvpn) can complete per-connection SSO via OpenVPN's standard WEB\_AUTH / AUTH\_PENDING protocol. Previously only the official desktop client could, so mobile/third-party clients got \`AUTH\_FAILED\`.
> 
> When enabled alongside \`sso\_auth\`, a tokenless client advertising \`IV\_SSO=webauth\` is sent \`client-pending-auth "WEB\_AUTH::\<root\>/key/request?state=..."\`, authenticates through Pritunl's existing \`/key/request -\> /key/callback -\> /success\` flow, and the held connection is approved via the existing \`server\_sso\_tokens\` mechanism — the same machinery the desktop client uses.
> 
> Opt-in (default off). Desktop-client, profile-download, and non-SSO flows are unchanged; no changes to \`handlers/sso.py\` or \`handlers/key.py\`. Requires an OpenVPN 2.6+ server (already shipped).
> 
> Tested on 1.34 with Google Workspace SSO: OpenVPN Connect -\> browser login -\> \`/success\` -\> connected.

It’s supported now !
