<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content

Okta Returns "The client is not authorized to use the provided grant type..." Error

API Access Management
Okta Classic Engine
Okta Identity Engine

Overview

During an authorization event, the system returns the following error message, indicating that the client application is not permitted to use the requested grant type. To resolve this error, the required grant type must be enabled both in the client application's settings and have a valid policy within the authorization server.

 
{
"error":"unauthorized_client",
"error_description":"The client is not authorized to use the provided grant type. [...]"
}
 

Applies To

  • Okta Identity Engine (OIE)
  • Okta Classic Engine
  • OAuth 2.0 / OpenID Connect (OIDC) applications
  • Custom Authorization Server

Cause

This error occurs when a client application attempts to use an OAuth 2.0 grant type (for example, Client Credentials, Authorization Code, or Refresh Token) that has not been explicitly enabled in that application's configuration, or in the authorization server.

Solution

How to enable the grant type for the application and its access policy?

 

To resolve this error, the required grant type must be enabled both in the client application's settings and have a valid policy within the authorization server.

To check the application's settings:

  1. Sign in to the Admin Console.
  2. Go to Applications > Applications.
  3. Select the client application that is experiencing the error.
  4. Select the General tab.
  5. In the General Settings section, click Edit.
  6. Locate the Grant Types section.

Grant Types section

  1. Select the checkbox for the grant type the application needs to use (for example, Client Credentials or Refresh Token).
  2. Click Save.

 

To check the authorization server's settings:

  1. Sign in to the Admin Console.
  2. Go to Security > API.
  3. Select the authorization server that is being used.
  4. Select the Access Policy tab.
  5. On the left-hand side, find the Policy that is being applied.

Policy

  1. In the bottom right, find the relevant Rule.
  2. Click the pencil button to edit the rule.

Edit rule

  1. Locate the Grant Types section.

Grant Types section

  1. Select the checkbox for the grant type the application needs to use (for example, Client Credentials or Interaction Code).
  2. Click Save.

Related References

Loading
Okta Returns "The client is not authorized to use the provided grant type..." Error | Okta Support