Skip to content

Reference

Errors

Symptom, cause and fix for each integration error, as observed on the current engine with the contract applied.

Match on the error code (standard OAuth). The error_description text belongs to the engine and can change.

SymptomCauseFix
Back at the app with error=invalid_scopea scope outside the contract: phone, roles, offline_access, address…request exactly openid profile email
Back at the app with error=invalid_request about code_challenge_methodno PKCE, or plaingenerate the PKCE pair; send code_challenge_method=S256
IdP error page (HTTP 400), no return to the appredirect_uri is not exactly a registered one: trailing slash, port, http for https, another pathuse the descriptor’s exact value, or change the descriptor by pull request
Error page: client not foundwrong client_id, or the descriptor is not applied yetcheck the client_id; after the merge, the IdP administration applies the clients
Back at the app with error=unauthorized_clientresponse_type=token (implicit flow)use response_type=code
Sign-in without a password promptan existing session at the IdP (single sign-on)expected
SymptomCauseFix
Token endpoint answers 401 unauthorized_clientwrong secret, or the old one after a rotationcheck the secret delivered for this environment
400 invalid_grant on the code exchangecode used or expired, redirect_uri differs from the request’s, or code_verifier does not match the challengea code works once; start the login again
400 invalid_grant on the refreshthe central session ended: account blocked, logout, 30 min idle, the 10 h ceiling, or an IdP restartdestroy the local session; answer 401; the person signs in again
400 unauthorized_client for grant_type=passwordthe password grant is disableduse Authorization Code with PKCE
Many sessions end at oncethe IdP restartedexpected: every session ends within 5 minutes
SymptomCauseFix
IdP error page (HTTP 400), no return to the apppost_logout_redirect_uri is not in postLogoutRedirectUrisadd it to the descriptor
Next login after logout gets in without a passwordthe app ended only its local sessionalso redirect to end_session_endpoint with id_token_hint
SymptomCauseFix
ID token validation fails on issthe app points to another issuer (a test environment, an old address)use the permanent issuer
nonce missing or mismatchedthe library did not send a noncesend one; some libraries do it only when asked
API answers 401 to a token that works in the appanother client’s token (different aud), an ID token, or expiredsend the app’s own access token; refresh it on expiry
API finds no name and email claimsnot in the access tokencall userinfo_endpoint with the access token
Invited person signs in and gets no accessemail_verified is false, or the invitation’s email differsthe person verifies the email at the IdP; compare emails case-insensitively