browser automation failed on saml login redirect while onboarding agent timed out
For teams automating SSO logins in browsers. Use when SAML redirects break automation. Not for SSO config errors.
Fix browser automation failing on SAML login redirect while the onboarding agent times out
TL;DR
The automation fails because SAML redirects bounce across domains and the agent's wait does not survive the trip. Wait for the post-login landing state, not a fixed URL, and persist the agent's progress across the redirect. The redirect is normal; the brittle wait is the bug.
The error
Browser automation failed
SAML login redirect failed; onboarding agent timed out waiting for login to complete.Use this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=browser automation failed on saml login redirect while onboarding agent timed out"Fix it
Step 1: Persist progress before the login
Save the agent's current step and data before navigating to SSO.Expected: State survives the redirect.
Step 2: Wait for landing state, not a URL
Wait for an element or state that proves login completed, rather than an exact URL.Expected: The wait survives redirect chains and URL variations.
Step 3: Allow cross-domain navigation
Make sure the automation context permits the IdP domain hops.Expected: The redirect chain completes instead of being blocked.
Step 4: Extend the login timeout
Give interactive logins a realistic deadline.Expected: Slow IdPs stop tripping the timeout.
Step 5: Verify the full flow
Run onboarding through a real SAML login.Expected: The agent resumes after login and finishes setup.
When this applies
- Browser automation fails on SAML redirects
- Onboarding agents time out during SSO logins
- You are automating browser-based SSO
When it doesn't
- The SAML config itself is broken (fix the SSO)
- The browser cannot reach the IdP (check network)
- Login succeeds but setup fails after (check the post-login steps)
Compatibility
Browser automation: Playwright, Puppeteer. SAML 2.0 logins.
Variant phrasings
browser automation saml redirect failed
Same failure. State persistence plus landing-state waits fix it.
puppeteer saml login redirect timeout
Redirect chains are slow and variable. Wait on state, not time.
playwright sso redirect agent timeout
Cross-domain hops need explicit waiting. Fixed sleeps miss them.
Why it happens
SAML login redirects bounce across multiple domains with variable timing, while automation scripts often wait for one exact URL with a short timeout. Any deviation, extra hop, slower IdP, and the wait fails. Waiting on the outcome state instead of the URL makes the flow robust.
Edge cases
- MFA push steps need much longer waits; separate them from the redirect wait
- Headless browsers can behave differently on IdP bot checks; test in your shipping mode
- Save screenshots at each redirect hop so failures are debuggable
If it still fails
- Run headed once and watch; the failure is usually visible within seconds.
- Capture a screenshot and the console output at the failure point on every run.
- Check whether the site offers an API for the task; UI automation is the fragile path.
- Test with a fresh browser profile to rule out cookie or cache state.
- If the site added bot protection, stop and use the sanctioned path. Do not work around it.
Prevention
- Prefer APIs over browser automation wherever the site offers one.
- Screenshot on every failure so flakes are diagnosable.
- Use resilient selectors and re-validate them on a schedule.
- Keep automation accounts' sessions and auth factors maintained.
- Rate-limit automation traffic so it never looks like an attack.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_iz0nj0EMuTX42sWZsQiKlQ