Skip to main content
Team & Access

Troubleshooting sign-in and access problems

When someone on your team can't get in — or gets in but sees a full-page notice instead of the portal — StackJack always shows a support code starting with SJ-. This page decodes the codes you'll see…

Written By Christopher Scaminaci

Last updated About 22 hours ago

When someone on your team can't get in — or gets in but sees a full-page notice instead of the portal — StackJack always shows a support code starting with SJ-. This page decodes the codes you'll see for sign-in and team-access problems, with the fix for each. (Connector-authorization errors have their own codes and are covered in the Connectors section.)

Two kinds of problem

  1. Sign-in failed — the person never got past the identity service. They land on the Authentication Error page with an SJ-AUTH-* code.
  2. Signed in, but restricted — sign-in worked, but their workspace access needs attention. Every portal page shows a full-page notice with an SJ-ACCESS-* code instead of content.

Both screens include a Contact Support link that pre-fills an email to support@stackjack.io with the support code — and, on the restricted-access notices, also the account name, the signed-in email, and the page (the Authentication Error page happens before sign-in completes, so it can only include the code). Have your teammate use the link rather than paraphrasing the error.

Authentication Error page (SJ-AUTH-*)

The Authentication Error page showing the support code, the "Try signing in again" button, and the Contact Support link
The Authentication Error page showing the support code, the "Try signing in again" button, and the Contact Support link

CodeWhat it meansWhat to try
SJ-AUTH-LOGIN-EXPIREDThe sign-in attempt sat unfinished for too longStart a fresh sign-in. This usually means an old login tab expired; there is normally nothing wrong with the account.
SJ-AUTH-LOGIN-STATE-LOSTThe callback did not carry the browser data needed to match the sign-in attemptStart a fresh sign-in instead of reusing an old link or bookmark. If it repeats, allow site cookies (including in private-browsing mode) or try another browser.
SJ-AUTH-OIDC-REMOTE-FAILUREThe sign-in round-trip with the identity service didn't completeSee the common causes below, then Try signing in again
SJ-AUTH-GENERICSign-in failed for an unclassified reasonTry signing in again; contact support with the code if it repeats

Common, benign causes of a failed sign-in round-trip:

  • A stale bookmark — the person bookmarked an intermediate sign-in URL instead of the portal itself. Fix: bookmark the portal home page and start there.
  • Cookie or tracking blockers — extensions or strict browser privacy settings that block cookies on redirects can break the sign-in handshake. Fix: allow cookies for the portal and identity domains, or try a normal browser profile.
  • Sitting on the sign-in page too long: a sign-in started but left idle for more than about 15 minutes expires. StackJack restarts an expired sign-in once by itself and takes you to the page you were going to, so this page appears only if the restart fails too. Fix: sign in again in one sitting.

If it fails repeatedly across browsers and networks, contact support with the code.

Restricted-access notices (SJ-ACCESS-*)

These appear after a successful sign-in. The person's identity is fine — it's their team access that needs an admin (usually you).

CodeNoticeWhy it happensThe fix (admin action)
SJ-ACCESS-AWAITING-APPROVALAwaiting ApprovalThey joined without an invite (self-registered via an AI-assistant sign-in) and are pendingApprove them: Team → their row → Edit Tools → select tools → Save. Full walkthrough: Approving self-registered members
SJ-ACCESS-NO-TOOLSNo Tools AssignedTheir own tool list is empty and they hold no custom role — commonly after a co-owner was demoted, or an admin cleared all tools. Someone who holds a role is never in this state, even with an empty list of their ownTeam → Edit Tools → assign tools, or Team → Edit Roles → assign a custom role
SJ-ACCESS-REVOKEDAccess RevokedTheir membership was deactivatedIf intended, nothing. Otherwise Team → Reactivate (on their deactivated row) or send a new invite. If your organization runs directory sync, read the note below first
SJ-ACCESS-INVITE-ENDEDInvitation Expired, or Invitation WithdrawnThey were invited but never joined: the invite ran out (invites last 7 days) before their first sign-in, or someone revoked it. The notice names your organizationSend them a new invite from the Team page. Resend cannot revive an expired invite, because it keeps the old expiry. Once they accept the new one, revoke the old row
SJ-ACCESS-NO-TENANTNo StackJack Account FoundTheir identity didn't match any StackJack accountHave them try signing in again first. If it persists: they may have signed in with the wrong account/email, their invite may have expired before their first sign-in (send a new invite from the Team page; Resend keeps the old expiry), or their identity is stranded outside your organization (see below)

When directory sync undoes a manual Reactivate, and when it does not

If your organization runs Directory sync, whether a hand-made Reactivate holds depends on why the person was deactivated. There are two cases and they behave differently:

  • Their Entra account is disabled or deleted, and they still match a mapping. The Reactivate does not hold. The next sync run deactivates them again, because a disabled account is deactivated whatever the provenance — including for someone you invited by hand. Re-enable the account in Entra instead.
  • They left every mapped group. The Reactivate does hold. Once the sync has settled a row it does not re-deactivate it, so the member stays active. If you want the sync to manage them again, put them back in a mapped group or change the mapping.

A Revoke Access you performed yourself is never reversed by the sync — it only ever undoes its own deactivations. If such a person matches a mapping again, the sync flags them for review rather than reactivating them.

The same problems, seen from the AI-assistant side

A member whose portal shows one of these notices will also find their AI assistant limited: pending or tool-less members can connect but only reach StackJack's built-in status tools, and revoked members are refused outright with a message to ask their admin for a new invite. The stackjack_session_info tool reports the member's status and is the fastest self-diagnosis step.

Stranded identities ("No StackJack Account Found" that won't go away)

If an invited person signed in before opening their invite email — most often through a federated identity provider — their identity can be created outside your organization, where it matches nothing. Symptoms:

  • Persistent SJ-ACCESS-NO-TENANT for a person you definitely invited.
  • An invite attempt failing with an error that mentions reconciling the identity — that refusal is deliberate, not a bug.

Before you contact support, check the person's row in Pending Invites on the Team page. If it shows an Expired badge, the invite ran out before their first sign-in, and the fix is a new invite from the Team page, not support.

Fix: contact support@stackjack.io with the person's email. StackJack relocates the identity into your organization; the person then redoes password setup (they'll get a fresh setup email) and signs in normally.

"Signups from this domain are not available"

If someone from your company tries to create a new StackJack account at the signup page and sees "Signups from this domain are not available. Please contact support.", their email domain has been restricted from self-service signups. This is a StackJack-side control, and depending on the restriction level it can also block paid-plan provisioning for new accounts on that domain.

What it does not do: it has no effect on your existing account or on signed-in team members.

What to do: if the domain restriction is unexpected, email support@stackjack.io from the affected domain. And remember — coworkers joining an existing account should be invited from the Team page, not sent to the signup form.

Escalation checklist

When you contact support about an access problem, include:

  1. The SJ- support code (use the pre-filled Contact Support link where offered).
  2. The affected person's email address.
  3. What they were doing (portal sign-in vs. connecting an AI assistant) and roughly when.