<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
0D5WR000029qnsz0AAOkta Classic EngineAuthenticationAnswered2026-09-22T15:10:11.000Z2026-09-20T10:35:20.000Z2026-09-22T15:10:11.000Z

how to Configure a custom application error page for OIDC apps

trying to redirect unassigned users to a custom error page which has been configured under customization-> application access error page. but this works for only the saml based apps not for the OIDC. is there any way to redirect the unassinged users to a custom error page for OIDC apps

 


  • Paul S. (Okta, Inc.)

    Hello @SrisivakumarR.72127 (Customer)​ Thank you for posting on our Community page!

     

    You are asking why custom error pages configured under Customization → Application Access Error Page work for SAML-based applications but not for OpenID Connect (OIDC) applications, and whether there is a way to redirect unassigned OIDC users to a custom error page.

     

    The custom error page feature in Okta is primarily designed for SAML applications. OIDC applications handle unassigned user scenarios differently due to the OAuth 2.0 protocol flow, which returns an error response to the application rather than displaying an Okta-hosted error page.

     

    Root Cause:

    SAML applications receive error pages directly from Okta's server, so the custom error page setting applies. OIDC applications, by contrast, follow the OAuth 2.0 authorization code flow and return an error code (such as access_denied or unauthorized_client) back to the application's redirect URI. This means the error handling occurs on the application side, not on Okta's side, so the custom error page setting does not apply.

     

    Official Workaround:

    For OIDC applications, you must handle the unassigned user scenario at the application level:

    1. Configure your OIDC application to catch the error response returned by Okta (typically an access_denied error code in the authorization response).
    2. Implement custom error handling in your application code to intercept this error and redirect the user to your custom error page. The application receives the error as a query parameter in the redirect URI (for example, ?error=access_denied).
    3. Parse the error response in your application and display your custom error page or redirect the user accordingly.
    4.  

    Alternatively, contact Okta Support to verify whether your specific use case qualifies for any protocol-specific configuration options or to explore whether a policy-based approach might work for your scenario.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best
  • Paul S. (Okta, Inc.)

    Hello @SrisivakumarR.72127 (Customer)​ Thank you for posting on our Community page!

     

    You are asking why custom error pages configured under Customization → Application Access Error Page work for SAML-based applications but not for OpenID Connect (OIDC) applications, and whether there is a way to redirect unassigned OIDC users to a custom error page.

     

    The custom error page feature in Okta is primarily designed for SAML applications. OIDC applications handle unassigned user scenarios differently due to the OAuth 2.0 protocol flow, which returns an error response to the application rather than displaying an Okta-hosted error page.

     

    Root Cause:

    SAML applications receive error pages directly from Okta's server, so the custom error page setting applies. OIDC applications, by contrast, follow the OAuth 2.0 authorization code flow and return an error code (such as access_denied or unauthorized_client) back to the application's redirect URI. This means the error handling occurs on the application side, not on Okta's side, so the custom error page setting does not apply.

     

    Official Workaround:

    For OIDC applications, you must handle the unassigned user scenario at the application level:

    1. Configure your OIDC application to catch the error response returned by Okta (typically an access_denied error code in the authorization response).
    2. Implement custom error handling in your application code to intercept this error and redirect the user to your custom error page. The application receives the error as a query parameter in the redirect URI (for example, ?error=access_denied).
    3. Parse the error response in your application and display your custom error page or redirect the user accordingly.
    4.  

    Alternatively, contact Okta Support to verify whether your specific use case qualifies for any protocol-specific configuration options or to explore whether a policy-based approach might work for your scenario.

     

    Thank you for reaching out to our Community and have a great day!

    --

    Help others in the community by liking or hitting Select as Best if this response helped you.

    Expand Post
    Selected as Best

Loading
how to Configure a custom application error page for OIDC apps