**TL;DR:** Organization login failures come in three flavors: the app requires an org but none was passed, the identifier format is wrong, or the invitation does not match the user. Prefer org_id in code. When using {organization_name} placeholders in callback URLs, the name must match exactly, including casing.

## The error

```text
text
{"error": "access_denied", "error_description": "Organization is required"}
```

## The fix

**TL;DR:** Organization login failures come in three flavors: the app requires an org but none was passed, the identifier format is wrong, or the invitation does not match the user. Prefer org_id in code. When using {organization_name} placeholders in callback URLs, the name must match exactly, including casing.

## The error

```text
{"error": "access_denied", "error_description": "Organization is required"}
```

# Organization errors

## The errors

- `{"error": "access_denied", "error_description": "Organization is required"}` or the login page shows an organization picker unexpectedly.
- `invalid_request`: the organization parameter was malformed.
- Invitation link errors: "Invitation not found", "already accepted", or the invitee lands in the wrong org.

## org_id vs org_name

The `organization` authorize parameter accepts either the org_id (`org_abc123`) or the organization name. Names are human-readable and can change; ids are stable. Prefer org_id in code. When using `{organization_name}` placeholders in callback URLs, the name must match exactly, including casing.

## Required organization

Dashboard > Organizations > your org, or the application settings, can require an organization for login. If required and the authorize call omits `organization`, login fails. Fix: pass `organization: org_xxx` in authorizationParams on every login call, or turn off the requirement if the app is multi-mode.

## Invitation failures

- Expired: invitations expire after 7 days by default. Resend from Dashboard > Organizations > Members > Invite.
- Wrong user: the invitation is tied to an email. If the invitee logs in with a different email or a social account with a different email, acceptance fails. The invited email must match the login identity.
- Already a member: re-inviting an existing member errors; check membership first.
- Connection mismatch: the invite specifies a connection; the user must authenticate through that connection.

## Just-in-time membership

Instead of invites, enable JIT: Organization > Connections > enable connection > turn on Just-In-Time membership. Users logging in through that connection auto-join. Fewer invites, fewer failures.

## Checklist

- organization param passed consistently (id form) on every login and silent-auth call.
- Invitation email matches the login identity; resend if expired.

## When to use this

- You are seeing this exact error message; match the block above, not just part of it.
- The failing call matches the scenario in the title: Organization errors.
- You want the fastest verified fix before digging through logs.

## When not to use this

- Your error text differs from the block above; close cousins often have different causes.
- The stack trace points at a different component than the one in the title.
- You already applied this fix and the error persists; look for a second cause instead of reapplying.

## Compatibility

- Not pinned to a specific version; follows current Organization behavior.

## Also seen as

- `invalid_request`