Azure API Management (APIM) developer portal signup/signin popup page times out after 60 seconds

curious7 281 Reputation points
2026-10-06T22:43:20.21+00:00

Azure API Management (APIM) developer portal signup/signin popup page times out after 60 seconds.

I used Developer tools to capture the browser trace and noticed the "popupBridgeTimeout" setting in the theme.js as per the attached screenshot. The line popupBridgeTimeout: userInputSystem?.popupBridgeTimeout || 6e4 seems to means "use the app's configured value, otherwise 60 seconds.". From my search it seems MSAL has a built-in default popup timeout constant is 60000 ms, and popupBridgeTimeout falls back to it when the app doesn't set one.

Q1:- Could this timeout be due to this setting or is there somewhere else I should be looking?
Q2:- And how can I increase that time?
Q3:- I am using Identity Experience Framework (IEF) policy with B2C. Could there be any setting in there that is causing this?

DeveloperPortal_AADB2C_Timeout

Azure API Management
Azure API Management

An Azure service that provides a hybrid, multi-cloud management platform for APIs.

0 comments No comments

1 answer

Sort by: Most helpful
  1. Manish Kumar 160 Reputation points
    2026-10-07T06:24:16.68+00:00

    Hello @curious7

    Please find the responses to your questions from the analysis I did.

    Q1: Is popupBridgeTimeout the cause?

    Most likely yes. The managed portal uses MSAL Browser v5, where windowHashTimeout was renamed to popupBridgeTimeout. MSAL defaults it to 60000 ms when the app doesn't set it. The timer starts when the popup opens and covers the whole B2C journey, so a sign-up with email verification or MFA that takes more than 60 seconds will time out.

    References:

    Q2: How do I increase it?

    The managed portal has no setting for this. The MSAL config is compiled into JavaScript that Microsoft hosts. Options:

    1. Self-host the open-source portal. In runAadB2CUserFlow() in src/services/aadServiceV2.ts, add system: { windowHashTimeout: 300000 } to the MSAL config. The repo currently ships msal-browser 2.x. Use popupBridgeTimeout only if you upgrade to MSAL v5. You then own the portal's maintenance and upgrades.
    2. Raise it with Microsoft through a support case or a GitHub issue asking for a configurable timeout. But keep in mind this will be a development change from Microsoft and may take months to implement and rollout

    References:

    Q3: Can an IEF/B2C setting cause this?

    Not directly. This is a client-side MSAL timer, and IEF session and token settings don't affect it. The policy can still contribute in two ways: long or slow steps that push the journey past 60 seconds, or a final redirect that doesn't return to the portal's origin. To find out which, enable JourneyInsights with Application Insights and check whether B2C finished the journey before the timeout fired.

    References:

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.