<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta 400 Bad Request Error: "The redirect_uri parameter must be a Login redirect URI in the client app settings."

API Access Management
Okta Classic Engine
Okta Identity Engine

Overview

A 400 Bad Request error occurs during the /authorize request of an Implicit Flow or Authorization Code Flow using OpenID Connect (OIDC) or OAuth 2.0 when the OIDC client lacks the redirect_uri value as a registered Sign-in redirect URI. Resolve this error by adding the exact redirect URI from the authorize request to the allowed Sign-in redirect URIs in the Okta Admin Console.

 

400 Bad Request

The 'redirect_uri' parameter must be a Login redirect URI in the client app settings.

 

Error Message

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine 
  • OpenID Connect (OIDC)
  • Authorize (GET /authorize) request
  • Implicit Flow
  • Authorization Code Flow

Cause

The OIDC client in Okta lacks the redirect_uri parameter value from the authorize request as an allowed Sign-in redirect URI.

Solution

What steps verify and update the redirect URI in the Okta Admin Console?

Verify the redirect URI from the authorize request and add it to the OIDC application settings in the Okta Admin Console.

  1. Identify the redirect_uri parameter in the authorize request.
  2. Navigate to Applications > Applications in the Okta Admin Console.
  3. Select the specific OIDC application.
  4. In the General tab, click Edit.
  5. Add the exact redirect URI from the authorize request to the Sign-in redirect URIs section.
    NOTE: The Sign-in redirect URIs must be an exact, case-sensitive match, including trailing slashes, with the URI from the authorize request.
  6. Click Save.

 General settings

 

Troubleshoot the redirect URI using the System Log.

Search the Okta System Log for specific events and review the debug context to find the exact redirect URI from the failed authorize request.

  1. Search the Okta System Log for these events using one of the following filters:
    • outcome.reason sw "illegal_redirect_uri"
  2. Click Expand All.
  3. Review the DebugContext section to find the exact redirect_uri from the failed authorize request.

Expanded event

 

Related References

Loading
Okta 400 Bad Request Error: "The redirect_uri parameter must be a Login redirect URI in the client app settings." | Okta Support