Users started getting HTTP 400 error after updating an application from Admin UI on versions 2025.8 and above.
- Okta Access Gateway Versions 2025.8 and above
- Host Header
In 2025.8, an enhancement was added to support host headers that require port numbers. When the application is edited for the first time in version 2025.8 or later, and the host header is set to a private domain, the Admin UI will evaluate the host header value based on the protected resource. The evaluated host header will be sent to the backend application through OAG at the time of access.
In case the host header is not evaluated correctly, then the backend application OR OAG will return a HTTP 400 error.
- Edit the application.
- Expand the protected resource section.
- Make sure the host header value is correctly set.
- Save the application.
Please contact Okta Support if the issue persists even after setting the correct host header.
