Okta Returns "One or more scopes are not configured for the authorization server resource" Error
Last Updated:
Overview
An invalid scope error occurs when making an /authorize call because a requested scope does not exist or is incompatible with the Okta org authorization server or the custom authorization server. Resolve this issue by determining the authorization server type in use and configuring the correct scopes. The following error occurs during the /authorize call:
{"error": "invalid_scope", "error_description": "One or more scopes are not configured for the authorization server resource."}
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OpenID Connect (OIDC)
- Authorization servers
- Scopes
Cause
This error occurs when using a scope that does not exist or is incompatible with either the Okta org authorization server or the custom authorization server.
Solution
The Authorization Server Type Determines the Available Scopes
Determine the active authorization server type by reviewing the Available authorization server types documentation.
How are scopes configured for an Okta org authorization server?
Okta org authorization servers do not support custom scopes. Review the following example of an /authorize request that includes the openid scope required for any OpenID Connect (OIDC) flow.
https://<OktaDomainName>/oauth2/v1/authorize?
client_id=0oabucvyc38HLL1ef0h7&
response_type=code&scope=openid&
redirect_uri=https%3A%2F%2Fexample.com&
state=state-296bc9a0-a2a2-4a57-be1a-d0e2fd9bb601
If the openid scope value is not present, the request may be a valid OAuth 2.0 request, but it is not an OIDC request. See Scope values for more information.
Review the following example of an /authorize request that obtains scoped OAuth 2.0 access tokens.
https://<OktaDomainName>/oauth2/v1/authorize?
client_id=0oan47pj9BsB30h7&
response_type=code&
scope=okta.users.read&
redirect_uri=https%3A%2F%2Fexample.com&
state=state-296bc9a0-a2a2-4a57-be1a-d0e2fd9bb601
Each access token enables the bearer to perform specific actions on specific Okta endpoints. The scopes within the access token control that ability. For a complete list of available scopes, see the OAuth 2.0 scopes documentation. For more information, refer to the OAuth for Okta and OAuth for Okta with a service app documentation.
Custom Authorization Servers Require Specific Scope Configurations
When using a custom authorization server, ensure the required scopes exist, and an appropriate access policy and rule permit them. For configuration steps in Okta, see Create Scopes.
The /oauth2/default/v1/authorize endpoint is a pre-created custom authorization server and supports the creation of custom scopes. Review the following example of an /authorize request that includes a custom scope named customScope for a the Default Custom Authorization server.
https://<OktaDomainName>/oauth2/default/authorize?
client_id=0oabucvyc38HLL1ef0h7&
response_type=code&scope=openid+customScope&
redirect_uri=https%3A%2F%2Fexample.com&
state=state-296bc9a0-a2a2-4a57-be1a-d0e2fd9bb601
It is also possible to create a new custom authorization server and configure it with custom scopes. Review the following example of an /authorize request that includes a custom scope named customScope for a personally configured custom authorization server. Note that the <authorizationServerId> is a unique identifier (for example, aus9o8wzkhckw9TLa0h7z)
https://<OktaDomainName>/oauth2/aus9o8wzkhckw9TLa0h7z/authorize?
client_id=0oabucvyc38HLL1ef0h7&
response_type=code&scope=openid+customScope&
redirect_uri=https%3A%2F%2Fexample.com&
state=state-296bc9a0-a2a2-4a57-be1a-d0e2fd9bb601
Related References
- Authorization Servers Overview
- Customize Authorization Server Guide
- Creating a Scope for an Authorization Server in Okta
- API Access Management
- OAuth 2.0 Scopes
