Okta 400 Bad Request Error: "The redirect_uri parameter must be a Login redirect URI in the client app settings."
Last Updated:
Overview
A 400 Bad Request error occurs during the /authorize request of an Implicit Flow or Authorization Code Flow using OpenID Connect (OIDC) or OAuth 2.0 when the OIDC client lacks the redirect_uri value as a registered Sign-in redirect URI. Resolve this error by adding the exact redirect URI from the authorize request to the allowed Sign-in redirect URIs in the Okta Admin Console.
400 Bad Request
The 'redirect_uri' parameter must be a Login redirect URI in the client app settings.
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- OpenID Connect (OIDC)
- Authorize (
GET /authorize) request - Implicit Flow
- Authorization Code Flow
Cause
The OIDC client in Okta lacks the redirect_uri parameter value from the authorize request as an allowed Sign-in redirect URI.
Solution
What steps verify and update the redirect URI in the Okta Admin Console?
Verify the redirect URI from the authorize request and add it to the OIDC application settings in the Okta Admin Console.
- Identify the
redirect_uriparameter in the authorize request. - Navigate to Applications > Applications in the Okta Admin Console.
- Select the specific OIDC application.
- In the General tab, click Edit.
- Add the exact redirect URI from the authorize request to the Sign-in redirect URIs section.
NOTE: The Sign-in redirect URIs must be an exact, case-sensitive match, including trailing slashes, with the URI from the authorize request. - Click Save.
Troubleshoot the redirect URI using the System Log.
Search the Okta System Log for specific events and review the debug context to find the exact redirect URI from the failed authorize request.
- Search the Okta System Log for these events using one of the following filters:
outcome.reason sw "illegal_redirect_uri"
- Click Expand All.
- Review the DebugContext section to find the exact
redirect_urifrom the failed authorize request.
