{"record":{"id":"03cff46323608b64","repo":"spring-projects/spring-security","slug":"client-registration-not-found","errorCode":"client_registration_not_found","errorMessage":"Client Registration not found with Id: ${registrationId}","messagePattern":"Client Registration not found with Id: (.+?)","errorType":"error_code","errorClass":"OAuth2AuthenticationException","httpStatus":null,"severity":"error","filePath":"oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/OAuth2LoginAuthenticationFilter.java","lineNumber":186,"sourceCode":"\t\t\tthrows AuthenticationException {\n\t\tMultiValueMap<String, String> params = OAuth2AuthorizationResponseUtils.toMultiMap(request.getParameterMap());\n\t\tif (!OAuth2AuthorizationResponseUtils.isAuthorizationResponse(params)) {\n\t\t\tOAuth2Error oauth2Error = new OAuth2Error(OAuth2ErrorCodes.INVALID_REQUEST);\n\t\t\tthrow new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString());\n\t\t}\n\t\tOAuth2AuthorizationRequest authorizationRequest = this.authorizationRequestRepository\n\t\t\t.removeAuthorizationRequest(request, response);\n\t\tif (authorizationRequest == null) {\n\t\t\tOAuth2Error oauth2Error = new OAuth2Error(AUTHORIZATION_REQUEST_NOT_FOUND_ERROR_CODE);\n\t\t\tthrow new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString());\n\t\t}\n\t\tString registrationId = authorizationRequest.getAttribute(OAuth2ParameterNames.REGISTRATION_ID);\n\t\tAssert.hasText(registrationId, \"registrationId cannot be empty\");\n\t\tClientRegistration clientRegistration = this.clientRegistrationRepository.findByRegistrationId(registrationId);\n\t\tif (clientRegistration == null) {\n\t\t\tOAuth2Error oauth2Error = new OAuth2Error(CLIENT_REGISTRATION_NOT_FOUND_ERROR_CODE,\n\t\t\t\t\t\"Client Registration not found with Id: \" + registrationId, null);\n\t\t\tthrow new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString());\n\t\t}\n\t\t// @formatter:off\n\t\tString redirectUri = UriComponentsBuilder.fromUriString(UrlUtils.buildFullRequestUrl(request))\n\t\t\t\t.replaceQuery(null)\n\t\t\t\t.build()\n\t\t\t\t.toUriString();\n\t\t// @formatter:on\n\t\tOAuth2AuthorizationResponse authorizationResponse = OAuth2AuthorizationResponseUtils.convert(params,\n\t\t\t\tredirectUri);\n\t\tObject authenticationDetails = this.authenticationDetailsSource.buildDetails(request);\n\t\tOAuth2LoginAuthenticationToken authenticationRequest = new OAuth2LoginAuthenticationToken(clientRegistration,\n\t\t\t\tnew OAuth2AuthorizationExchange(authorizationRequest, authorizationResponse));\n\t\tauthenticationRequest.setDetails(authenticationDetails);\n\t\tOAuth2LoginAuthenticationToken authenticationResult = (OAuth2LoginAuthenticationToken) this\n\t\t\t.getAuthenticationManager()\n\t\t\t.authenticate(authenticationRequest);\n\t\tOAuth2AuthenticationToken oauth2Authentication = this.authenticationResultConverter\n\t\t\t.convert(authenticationResult);","sourceCodeStart":168,"sourceCodeEnd":204,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/OAuth2LoginAuthenticationFilter.java#L168-L204","documentation":"After loading the stored authorization request, the filter reads its registration_id attribute and looks up the ClientRegistration in the ClientRegistrationRepository. This error means the registration id recorded in the authorization request no longer resolves to a registered client.","triggerScenarios":"The registration was removed or renamed in configuration between the time the login flow started and the callback arrived (stale session), or the InMemoryClientRegistrationRepository was rebuilt/redeployed with a different id.","commonSituations":"Renaming spring.security.oauth2.client.registration.<id> during a rolling redeploy while users hold active sessions; dynamically registered clients being evicted; typo in repository setup when building registrations programmatically.","solutions":["Keep registration ids stable across deploys, or invalidate old sessions on redeploy","Confirm the registration id used in the authorization request exists in your ClientRegistrationRepository (check InMemoryClientRegistrationRepository contents)","Restart the login flow so a fresh authorization request referencing a valid registration is created"],"exampleFix":null,"handlingStrategy":"validation","validationCode":"ClientRegistration cr = clientRegistrationRepository.findByRegistrationId(id);\nif (cr == null) {\n    throw new IllegalStateException(\"Unknown registration id: \" + id);\n}","typeGuard":null,"tryCatchPattern":"catch (OAuth2AuthenticationException e) {\n    if (\"client_registration_not_found\".equals(e.getError().getErrorCode())) {\n        // clear session and restart the login flow\n    }\n}","preventionTips":["Keep registration ids stable across deployments","Invalidate/rotate sessions when client registration config changes","Verify InMemoryClientRegistrationRepository contents match configured ids"],"tags":["oauth2","spring-security","configuration","registration"],"backgroundTag":"resource-not-found","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}