App login degradation
Incident Report for Yousign
Postmortem

Incident Impact

Logins to v3 application (https://yousign.app) encountered a large number of errors (from 50 to 90% failure rate depending on the time) between 17:00 UTC+1 and 22:00 UTC+1 on Thursday, December 16th. Users, managers and administrators were still able to log in after several attempts and users with a session were not impacted. Signers were able to access and sign their documents during this.

Our v2 application (https://webapp.yousign.com) was almost not impacted because the technical implementation is different.

Root Cause Analysis

We use Auth0 as our identity provider to manage accounts and multiple authentication systems to our application.

Unfortunately, our provider experienced a first incident that started at 17:00 UTC+1 and escalated at 18:00 UTC+1. Our alert system warned us at 18:30 UTC+1 and Auth0 finally communicated about the incident exactly at 19:19 UTC+1 before backdating the first item. Their API endpoint /userinfo, called at each connection, was not responding correctly which led to an unanticipated behavior from us and the display of a white error page with the message "Authentication Required".

Auth0 finally fixed this first incident between 21:00 UTC+1 and 22:00 UTC+1 but a second incident occurred during this period. Their APIs were responding very slowly but it was still possible to login to our application by being patient.

Finally, the situation was resolved at 22:00 UTC+1 and the authentication system of v3 application was back fully functional.

Correction

During the incident, we notified our identity provider and monitored their communications in order to provide you as much information as possible on our status page.

We will be adding new log alerts in order to be able to communicate more quickly.

Finally, we will create a comprehensive error page to guide users.

Posted Dec 20, 2021 - 10:21 CET

Resolved
We close the incident. To recap, only user, manager and administrator logins were affected by 2 incidents at our identity provider Auth0. Signers were able to access and sign their documents normally during this. We apologize for the inconvenience and will write a post-mortem in the next few days.
Posted Dec 16, 2021 - 22:21 CET
Update
Our identity provider Auth0 after fixing the errors on their API experienced a severe slowdown for several minutes. The situation seems to be stable now, we continue our monitoring.
Posted Dec 16, 2021 - 22:04 CET
Update
Our authentication service is no longer experiencing errors but may be slow to respond.
Posted Dec 16, 2021 - 21:30 CET
Monitoring
A fix has been implemented by our identity provider Auth0. We are monitoring the results.
Posted Dec 16, 2021 - 21:22 CET
Identified
Some customers may experience an issue on logging into ours v2 or v3 applications since 5pm. The incident is identified at our identity provider Auth0. You should try to reconnect in case of error.

We will update you again shortly here.

If you have urgent questions, please contact our support team by sending an email to support@yousign.com.
Posted Dec 16, 2021 - 17:00 CET
This incident affected: Yousign V3 (APP V3 - https://yousign.app) and Yousign V2 (APP V2 - https://webapp.yousign.com).