<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D54z00009WnZOlCANOkta Classic EngineAuthenticationAnswered2024-04-17T10:25:24.000Z2023-08-16T14:33:51.000Z2023-08-17T16:47:58.000Z

g7mod (g7mod) asked a question.

Setting for requiring `state` parameter in request?

I am developing an OIDC integration with Okta. At one point, I got this error when authenticating:

 

> error: invalid_request

> error_description: The authentication request has an invalid 'state' parameter.

 

I understand this is for protection against CSRF attacks. My client was not setting this parameter, so I revised the client behavior to set it, and was able to authenticate.

 

Is this parameter required because of a particular setting in my Okta application? If so, which one?

 

Thanks in advance.


This question is closed.
Loading
Setting for requiring `state` parameter in request?