<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Support for Wildcard Redirect URIs

API Access Management
Okta Classic Engine
Okta Identity Engine

Overview

To allow wildcards within Sign-in redirect URIs for OpenID Connect (OIDC) applications, "Allow wildcard * in login URI redirect" must be enabled on the application. Note that wildcards are only supported for subdomains, in URLs that use the HTTPS protocol, and in Sign-in redirect URIs (not supported for Logout redirect URIs).

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • OpenID Connect (OIDC) applications
  • Sign-in Redirect URIs
  • Wildcards

Solution

Does Okta support wildcards in Sign-in redirect URIs?

 

Okta supports Wildcards in Sign-in Redirect URIs, but they must be explicitly enabled for a given application, either via the API or in the Okta Admin Console under Application > General Settings > Login > Allow wildcard * in login URI redirect

Allow wildcard * in login URI redirect

When the setting Allow wildcard * in login URI redirect is disabled, all redirect URIs must be absolute URIs and must not include a fragment component. 

With the setting Allow wildcard * in login URI redirect enabled (in the API,  settings.oauthClient.wildcard_redirect would be set to subdomain), then any configured redirect URIs may contain a single * character in the lowest-level domain (for example, https://redirect-*-domain.example.com/oidc/redirect) to act as a wildcard. The wildcard subdomain must have at least one subdomain between it and the top-level domain.

 

The wildcard can match valid hostname characters, but cannot span more than one domain.

For example, if https://redirect-*-domain.example.com/oidc/redirect is configured as a redirect URI, then https://redirect-1-domain.example.com/oidc/redirect and https://redirect-sub-domain.example.com/oidc/redirect match, but https://redirect-1.sub-domain.example.com/oidc/redirect does not match.


Important limitations and considerations

  • Wildcards are supported only with the HTTPS URI scheme.
  • Wildcards can only be used for subdomains (for example, https://redirect-*-domain.example.com).
  • Wildcards cannot be used in the folder path. For example, https://redirect.domain.example.com/*/redirect is not supported. 
  • Wildcards cannot be used for a port number. For example, https://redirect.domain.example.com:* is not supported.
  • Wildcards are not supported for Logout Redirect URIs.
  • Exercise caution when using wildcard subdomains, as it is considered an insecure practice and may allow malicious actors to have tokens or authorization codes sent to unexpected or attacker-controlled pages.

Related References

Loading
Okta Support for Wildcard Redirect URIs | Okta Support