Invalid_Client Error Returned When Requesting OAuth Token(s) in Okta
Last Updated:
Overview
An invalid_client error occurs when requesting an OAuth 2.0 token due to incorrect client credentials, mismatched tenant URLs, or an expired client secret. Resolve this error by verifying the client credentials, ensuring the tenant URLs match, and generating a new client secret in the Admin Console. These errors occur during an authentication attempt or when requesting a token.
Okta generates the following error message and image when an invalid client identifier is provided.
{
"errorCode": "invalid_client",
"errorSummary": "Invalid value for 'client_id' parameter."
}
Okta generates the following error message and image for an invalid client secret.
{
"error": "invalid_client",
"error_description": "The client secret supplied for a confidential client is invalid."
}
Okta generates the following error message and image for a general client authentication failure.
{
"error": "invalid_client",
"error_description": "Client authentication failed. Either the client or the client credentials are invalid."
}Applies To
- OAuth 2.0
- OpenID Connect (OIDC)
- API Authentication
- Okta Identity Engine (OIE)
- Classic
Cause
Configuration issues cause this error in the following ways:
- The
<client_id>or<client_secret>provided in the request is incorrect or does not match the application configuration. - The request omits the
<client_id>and<client_secret>from the Authorization Header, or the/tokenendpoint call uses an incorrect client authentication method. - The
/authorizeand/tokenendpoint requests go to different tenants (for example, one to<domain-123.okta.com>and the other to<domain-456.okta.com>). - An expired or revoked client secret causes the error.
Solution
What steps resolve the invalid_client error?
Verify the client credentials, tenant URLs, and authentication method by reviewing the application configuration, confirming the tenant URLs match, and checking the client authentication method.
- Verify that the
<client_id>and<client_secret>values used in the request exactly match the credentials listed in the application configuration. - Confirm that the tenant (for example,
https://<tenant>.okta.com) is the same for both the/authorizerequest and the/tokenrequest. - Verify that the
/tokenendpoint call uses the correct client authentication method.
Format the Authorization header for the client_secret_basic method by passing the client identifier and client secret as a Base64-encoded string. NOTE: For the client_secret_basic method, the Authorization header uses the following format.
Authorization: Basic ${Base64(<client_id>:<client_secret>)}
Generate the Base64-encoded string from the command line by executing the openssl base64 command.
echo -n '<client_id>:<client_secret>' | openssl base64
A new client secret resolves invalid existing secrets.
Generate a new client secret by navigating to the Applications section in the Admin Console, selecting the target application, generating the new secret in the General tab, and updating the external application configuration.
- In the Admin Console, go to Applications > Applications.
- Select the target application.
- Select the General tab.
- In the Client Secrets section, select Generate New Secret.
- Update the external application or service configuration with the newly generated secret.
