<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
Google Workspace Provisioning Error "POST https://accounts.google.com/o/oauth2/token returned a response status of 400 Bad Request"
Okta Integration Network
Overview

Google Workspace provisioning flow fails with the following error visible in the Okta dashboard: 

Automatic provisioning of user <username> to app Google Workspace failed: Failed to verify that the user exists. com.sun.jersey.api.client.UniformInterfaceException: POST https://accounts.google.com/o/oauth2/token returned a response status of 400 Bad Request


Error Message

 

Applies To
  • Google Workspace
  • Provisioning
  • Error
Cause
  • The Google Workspace administrator credentials used for creating the API connection are invalid.
  • The authentication token is invalid.
  • Non-approved third-party APIs are blocked from accessing the Google tenant.
Solution
  1. Enable the API Access checkbox in Google Workspace:

    1. Sign in to the Google Workspace admin console.
    2. Go to SecurityAccess and data control > API controls > MANAGE THIRD-PARTY APP ACCESS.

      MANAGE THIRD-PARTY APP ACCESS 
    3. In the Accessed Apps section, click View List.

View List button

    1. The Okta app can be found there. Verify that the Blocked option is not selected for the Okta App.
      Blocked option 
  1. Go to the Okta admin console and navigate to Applications > Applications > Google Workspace > Provisioning > Integration > then click the Edit button.

  2. Click Re-authenticate with Google Workspace.
    "Re-authenticate with Google Workspace" button 

  3. Enter the Google Workspace Admin account credentials:

    1. Enter the admin username.
    2. Enter the admin password.
    3. Review the list of permissions Google will grant Okta to perform in the Google Workspace tenant. If acceptable, click Allow.
  1. A message confirming successful authentication will be seen on the Provisioning page in Okta. Click Save.

  2. Attempt the failed tasks again. Navigate to Dashboard > Tasks. Any failed assignments should appear under Tasks
Tasks 
  1. After locating the failed task for the user that should be retried, click on Retry Selected

 

Related References

Loading
Google Workspace Provisioning Error "POST https://accounts.google.com/o/oauth2/token returned a response status of 400 Bad Request"