Troubleshooting sign-in and access problems
When someone on your team can't get in — or gets in but sees a full-page notice instead of the portal — StackJack always shows a support code starting with SJ-. This page decodes the codes you'll see…
Written By Christopher Scaminaci
Last updated About 22 hours ago
When someone on your team can't get in — or gets in but sees a full-page notice instead of the portal — StackJack always shows a support code starting with SJ-. This page decodes the codes you'll see for sign-in and team-access problems, with the fix for each. (Connector-authorization errors have their own codes and are covered in the Connectors section.)
Two kinds of problem
- Sign-in failed — the person never got past the identity service. They land on the Authentication Error page with an
SJ-AUTH-*code. - Signed in, but restricted — sign-in worked, but their workspace access needs attention. Every portal page shows a full-page notice with an
SJ-ACCESS-*code instead of content.
Both screens include a Contact Support link that pre-fills an email to support@stackjack.io with the support code — and, on the restricted-access notices, also the account name, the signed-in email, and the page (the Authentication Error page happens before sign-in completes, so it can only include the code). Have your teammate use the link rather than paraphrasing the error.
Authentication Error page (SJ-AUTH-*)

Common, benign causes of a failed sign-in round-trip:
- A stale bookmark — the person bookmarked an intermediate sign-in URL instead of the portal itself. Fix: bookmark the portal home page and start there.
- Cookie or tracking blockers — extensions or strict browser privacy settings that block cookies on redirects can break the sign-in handshake. Fix: allow cookies for the portal and identity domains, or try a normal browser profile.
- Sitting on the sign-in page too long: a sign-in started but left idle for more than about 15 minutes expires. StackJack restarts an expired sign-in once by itself and takes you to the page you were going to, so this page appears only if the restart fails too. Fix: sign in again in one sitting.
If it fails repeatedly across browsers and networks, contact support with the code.
Restricted-access notices (SJ-ACCESS-*)
These appear after a successful sign-in. The person's identity is fine — it's their team access that needs an admin (usually you).
When directory sync undoes a manual Reactivate, and when it does not
If your organization runs Directory sync, whether a hand-made Reactivate holds depends on why the person was deactivated. There are two cases and they behave differently:
- Their Entra account is disabled or deleted, and they still match a mapping. The Reactivate does not hold. The next sync run deactivates them again, because a disabled account is deactivated whatever the provenance — including for someone you invited by hand. Re-enable the account in Entra instead.
- They left every mapped group. The Reactivate does hold. Once the sync has settled a row it does not re-deactivate it, so the member stays active. If you want the sync to manage them again, put them back in a mapped group or change the mapping.
A Revoke Access you performed yourself is never reversed by the sync — it only ever undoes its own deactivations. If such a person matches a mapping again, the sync flags them for review rather than reactivating them.
The same problems, seen from the AI-assistant side
A member whose portal shows one of these notices will also find their AI assistant limited: pending or tool-less members can connect but only reach StackJack's built-in status tools, and revoked members are refused outright with a message to ask their admin for a new invite. The stackjack_session_info tool reports the member's status and is the fastest self-diagnosis step.
Stranded identities ("No StackJack Account Found" that won't go away)
If an invited person signed in before opening their invite email — most often through a federated identity provider — their identity can be created outside your organization, where it matches nothing. Symptoms:
- Persistent
SJ-ACCESS-NO-TENANTfor a person you definitely invited. - An invite attempt failing with an error that mentions reconciling the identity — that refusal is deliberate, not a bug.
Before you contact support, check the person's row in Pending Invites on the Team page. If it shows an Expired badge, the invite ran out before their first sign-in, and the fix is a new invite from the Team page, not support.
Fix: contact support@stackjack.io with the person's email. StackJack relocates the identity into your organization; the person then redoes password setup (they'll get a fresh setup email) and signs in normally.
"Signups from this domain are not available"
If someone from your company tries to create a new StackJack account at the signup page and sees "Signups from this domain are not available. Please contact support.", their email domain has been restricted from self-service signups. This is a StackJack-side control, and depending on the restriction level it can also block paid-plan provisioning for new accounts on that domain.
What it does not do: it has no effect on your existing account or on signed-in team members.
What to do: if the domain restriction is unexpected, email support@stackjack.io from the affected domain. And remember — coworkers joining an existing account should be invited from the Team page, not sent to the signup form.
Escalation checklist
When you contact support about an access problem, include:
- The
SJ-support code (use the pre-filled Contact Support link where offered). - The affected person's email address.
- What they were doing (portal sign-in vs. connecting an AI assistant) and roughly when.
More in Team & Access
Team roles and what each role can doInviting teammates: the invite lifecycle from email to first sign-inSelf-registration and approving new membersManaging members: tools, roles, suspension, and reactivationStill need help? Ask the team