{"record":{"id":"19992deb5e3ad7f0","repo":"spring-projects/spring-security","slug":"invalid-authorization-grant-type-granttype-fo-19992d","errorCode":null,"errorMessage":"Invalid Authorization Grant Type (${grantType}) for Client Registration with Id: ${registrationId}","messagePattern":"Invalid Authorization Grant Type \\((.+?)\\) for Client Registration with Id: (.+?)","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/server/DefaultServerOAuth2AuthorizationRequestResolver.java","lineNumber":210,"sourceCode":"\t\t\t\t\t.attributes((attrs) ->\n\t\t\t\t\t\t\tattrs.put(OAuth2ParameterNames.REGISTRATION_ID, clientRegistration.getRegistrationId()));\n\t\t\t// @formatter:on\n\t\t\tif (!CollectionUtils.isEmpty(clientRegistration.getScopes())\n\t\t\t\t\t&& clientRegistration.getScopes().contains(OidcScopes.OPENID)) {\n\t\t\t\t// Section 3.1.2.1 Authentication Request -\n\t\t\t\t// https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest\n\t\t\t\t// scope\n\t\t\t\t// REQUIRED. OpenID Connect requests MUST contain the \"openid\" scope\n\t\t\t\t// value.\n\t\t\t\tapplyNonce(builder);\n\t\t\t}\n\t\t\tif (ClientAuthenticationMethod.NONE.equals(clientRegistration.getClientAuthenticationMethod())\n\t\t\t\t\t|| clientRegistration.getClientSettings().isRequireProofKey()) {\n\t\t\t\tDEFAULT_PKCE_APPLIER.accept(builder);\n\t\t\t}\n\t\t\treturn builder;\n\t\t}\n\t\tthrow new IllegalArgumentException(\n\t\t\t\t\"Invalid Authorization Grant Type (\" + clientRegistration.getAuthorizationGrantType().getValue()\n\t\t\t\t\t\t+ \") for Client Registration with Id: \" + clientRegistration.getRegistrationId());\n\t}\n\n\t/**\n\t * Expands the {@link ClientRegistration#getRedirectUri()} with following provided\n\t * variables:<br/>\n\t * - baseUrl (e.g. https://localhost/app) <br/>\n\t * - baseScheme (e.g. https) <br/>\n\t * - baseHost (e.g. localhost) <br/>\n\t * - basePort (e.g. :8080) <br/>\n\t * - basePath (e.g. /app) <br/>\n\t * - registrationId (e.g. google) <br/>\n\t * - action (e.g. login) <br/>\n\t * <p/>\n\t * Null variables are provided as empty strings.\n\t * <p/>\n\t * Default redirectUri is:","sourceCodeStart":192,"sourceCodeEnd":228,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/server/DefaultServerOAuth2AuthorizationRequestResolver.java#L192-L228","documentation":"Reactive counterpart of the servlet resolver: DefaultServerOAuth2AuthorizationRequestResolver.getBuilder (called from getClientRegistrations) throws IllegalArgumentException when the ClientRegistration's AuthorizationGrantType is not authorization_code (or JWT bearer), because WebFlux OAuth2 login only supports the browser redirect flow.","triggerScenarios":"A reactive spring.security.oauth2.client.registration entry declares grant-type client_credentials (or another non-redirect grant) and the /oauth2/authorization/{registrationId} endpoint is hit.","commonSituations":"Reusing a servlet client_credentials registration in a WebFlux app; YAML grant-type typos; attempting OAuth2 login with token/credential flows that require programmatic token retrieval instead.","solutions":["Set the registration to authorization_code or remove the grant-type field to use the default","Fetch client_credentials tokens programmatically via WebClient + ServerOAuth2AuthorizedClientExchangeFilterFunction with a ClientProvider, not via the login redirect","Implement a custom ServerOAuth2AuthorizationRequestResolver if a non-standard grant is genuinely needed"],"exampleFix":"// before\nspring.security.oauth2.client.registration.myclient.authorization-grant-type: client_credentials\n// after\nspring.security.oauth2.client.registration.myclient.authorization-grant-type: authorization_code","handlingStrategy":"validation","validationCode":"if (!AuthorizationGrantType.AUTHORIZATION_CODE.equals(registration.getAuthorizationGrantType())) {\n    throw new IllegalStateException(\"Reactive OAuth2 login requires authorization_code grant for \" + registration.getRegistrationId());\n}","typeGuard":null,"tryCatchPattern":null,"preventionTips":["Omit grant-type in reactive registration config so it defaults to authorization_code","Handle client_credentials tokens via ServerOAuth2AuthorizedClientExchangeFilterFunction, not login redirects","Audit grant-type strings for typos"],"tags":["oauth2","webflux","spring-security","grant-type"],"backgroundTag":"invalid-enum-value","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}