Logout not clearing session cookies in React + Frappe OAuth app

Hi,

I’m using a React app with Frappe OAuth.
Login works fine, but after logout, when I click Login with Frappe, it directly logs into the previously logged-in user instead of showing the login page.

  • If I manually clear cookies in the browser console, it works as expected (redirects to OAuth login page).

What I tried

  • Clearing localStorage/sessionStorage → no effect.
  • Setting document.cookie to clear sid → not working (cookie is HttpOnly).
  • Considering /api/method/logout with credentials: "include".

Question

What’s the correct way to handle logout in React + Frappe OAuth so session cookies are cleared properly?

try this

fetch(“https://your-frappe-site.com/api/method/logout”, {
method: “GET”,
credentials: “include”
}).then(() => {
// also clear your React app’s auth state
localStorage.clear();
sessionStorage.clear();
});

Thanks for the suggestion.I tried using
fetch(“http://localhost:8000/api/method/logout”, {
method: “GET”,
credentials: “include”
}).then(() => {
localStorage.clear();
sessionStorage.clear();
});
The request is going through, but the sid cookie is not being cleared automatically. The user remains logged in until I manually clear cookies from the browser.

Try to redirect to https://frappe.app/?cmd=web_logout if that works for you. You will land on frappe app’s site.

Thanks for the suggestion .

I tried https://frappe.app/?cmd=web_logout. It does clear the session, but the behavior is not smooth for my use case:

  • When I hit that URL, it redirects me to the Frappe landing page.
  • From there, I still need to press Logout again and then refresh before I finally reach the login page.
  • What I want instead is: when a user presses Logout in my React app, the session should be cleared on Frappe and the user should be redirected straight to the Frappe login screen, not the landing page.

Basically, I need the flow to be:

React App → Logout → Frappe clears session → Immediately redirect to OAuth login page.

Is there a way to achieve this, maybe by passing a redirect-to parameter with ?cmd=web_logout, or using another logout endpoint that supports jumping directly to login?

@karthikdhumala @revant_one
Hi there, I am encountering a similar issue in my React Native mobile app. If you managed to find a solution or a workaround, would you mind sharing it? It would be greatly appreciated. Thanks!

reference : How to force re-authentication in OAuth2 (React Native) without manual browser logout?