Okta Error "The requested feature is not enabled in this environment" When Attempting to Log Into OpenID Connect Application
Last Updated:
Overview
A 400 Bad Request error occurs when attempting to authenticate with Okta using OpenID Connect (OIDC). This issue happens because the authentication request targets a Custom Authorization Server endpoint without the API Access Management feature enabled. Resolve this error by switching to the Okta Org Authorization Server or acquiring the API Access Management feature.
Error Code:
server_error
Error Description:
Your request resulted in an error. The requested feature is not enabled in this environment.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OpenID Connect (OIDC)
- Application Programming Interface (API)
- API Access Management
Cause
The authentication request is directed to a Custom Authorization Server endpoint (for example, https://org.okta.com/oauth2/default/v1/authorize). Using Custom Authorization Servers (including the default authorization server) requires the API Access Management feature. If the Okta organization does not have API Access Management enabled, the request is rejected with a 400 error code.
Solution
Which authorization server URL resolves the error?
The appropriate solution depends on the architecture and authentication requirements:
Option 1: Switch to the Okta Org Authorization Server
To perform Single Sign-On (SSO) with Okta for OpenID Connect applications or to get an access token for Okta APIs, use the Okta Org Authorization Server.
Update the configuration in the application or Service Provider (SP) to use the Org Authorization Server endpoint (remove /default from the path):
-
Org Authorization Server Endpoint:
https://org.okta.com/oauth2/v1/authorize.
Option 2: Acquire API Access Management for Custom Authorization Servers
If external APIs require access tokens for protection, or if the Service Provider (SP) is hardcoded to use a Custom Authorization Server endpoint (for example, https://org.okta.com/oauth2/default/v1/authorize), a Custom Authorization Server is necessary.
Because API Access Management is an additional paid feature, contact the Okta Account team to discuss feature licensing and pricing options for enabling Custom Authorization Servers in the environment.
Related References
- Authorization servers | Concepts | Okta Developer
- Composing a base URL | Okta Developer
- When to Use the Org Authorization Server vs a Custom Authorization Server in Okta | Okta Support Center
- Okta 401 Permissions Error During OIDC Application Login or Custom Authorization Server Configuration | Okta Support Center
