{"record":{"id":"1a277a5c846c42df","repo":"dotnet/aspnetcore","slug":"could-not-load-settings-from-settings-configura","errorCode":null,"errorMessage":"Could not load settings from '${settings.configurationEndpoint}'","messagePattern":"Could not load settings from '(.+?)'","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"src/Components/WebAssembly/WebAssembly.Authentication/src/Interop/AuthenticationService.ts","lineNumber":491,"sourceCode":"    }\n\n    public static async completeSignOut(url: string) {\n        let operation = this._pendingOperations[url];\n        if (!operation) {\n            operation = AuthenticationService.instance.completeSignOut(url);\n            await operation;\n            delete this._pendingOperations[url];\n        }\n\n        return operation;\n    }\n\n    private static async createUserManager(settings: OidcAuthorizeServiceSettings): Promise<UserManager> {\n        let finalSettings: UserManagerSettings;\n        if (isApiAuthorizationSettings(settings)) {\n            const response = await fetch(settings.configurationEndpoint);\n            if (!response.ok) {\n                throw new Error(`Could not load settings from '${settings.configurationEndpoint}'`);\n            }\n\n            const downloadedSettings = await response.json();\n\n            finalSettings = downloadedSettings;\n        } else {\n            if (!settings.scope) {\n                settings.scope = settings.defaultScopes.join(' ');\n            }\n\n            if (settings.response_type === null) {\n                // If the response type is not set, it gets serialized as null. OIDC-client behaves differently than when the value is undefined, so we explicitly check for a null value and remove the property instead.\n                delete settings.response_type;\n            }\n\n            finalSettings = settings;\n        }\n","sourceCodeStart":473,"sourceCodeEnd":509,"githubUrl":"https://github.com/dotnet/aspnetcore/blob/3600ca084e9c8b5f4174fc5e747f4c52d2100806/src/Components/WebAssembly/WebAssembly.Authentication/src/Interop/AuthenticationService.ts#L473-L509","documentation":"In the OIDC-based Blazor WebAssembly Authentication service (RemoteAuthentication / OidcAuthorizeService), when configured with API-authorization settings it fetches the OIDC discovery document from settings.configurationEndpoint to build the UserManager settings. If the fetch returns a non-OK HTTP status (!response.ok), the configuration cannot be loaded and the service throws, halting user-manager creation.","triggerScenarios":"Thrown at line 491 inside createUserManager when isApiAuthorizationSettings(settings) is true and the fetch to settings.configurationEndpoint returns a non-2xx status. Happens at startup when the OIDC config endpoint is unreachable or returns an error.","commonSituations":"The application's OIDC configuration endpoint (typically /_configuration/{AppName}) returns 404 because server-side AddOidc / API authorization was not wired correctly; the endpoint requires auth and returns 401/403; a network/proxy/CORS issue blocks the request; the SPA is hosted separately from the API and the configuration URL is misconfigured; running in an environment where the host base path differs (subdirectory hosting).","solutions":["Open the configurationEndpoint URL directly in a browser/devtools to see the actual status and message (404, 401, etc.).","Ensure server-side AddApiAuthorization / AddOidc is registered and the SPA client name matches {ApplicationName} used by the client.","Check that the configurationEndpoint URL is correct relative to the app's base href (subdirectory hosting often needs adjusting).","Verify network/CORS/proxy reachability to the endpoint; confirm no auth requirement on the configuration route."],"exampleFix":"// before: misconfigured endpoint returning 404\nconst settings = { configurationEndpoint: '/_configuration/WrongName' };\n// after: match the server-registered application name and base path\nconst settings = { configurationEndpoint: `/_configuration/${appName}` };\n// and on the server:\nservices.AddApiAuthorization(options => options.ProviderOptions.ConfigurationEndpoint = $\"/_configuration/{appName}\");","handlingStrategy":"validation","validationCode":"// Before constructing the UserManager, validate the configuration endpoint is reachable\nasync function configurationReachable(url: string): Promise<boolean> {\n  try {\n    const r = await fetch(url);\n    return r.ok;\n  } catch { return false; }\n}\nif (!(await configurationReachable(settings.configurationEndpoint))) {\n  // surface a clear startup error with the URL and status\n  throw new Error(`OIDC configuration endpoint not reachable: ${settings.configurationEndpoint}`);\n}","typeGuard":null,"tryCatchPattern":"try {\n  await createUserManager(settings);\n} catch (e) {\n  if (/Could not load settings/i.test((e as Error).message)) {\n    // log the endpoint URL, check AddApiAuthorization registration, then guide the user\n    console.error('OIDC config load failed for', settings.configurationEndpoint);\n  }\n  throw e;\n}","preventionTips":["Verify AddApiAuthorization / AddOidc is registered server-side and the app name matches.","Open the configurationEndpoint URL in a browser to inspect the actual status.","Account for subdirectory hosting when forming the configurationEndpoint URL.","Ensure network/CORS/proxy paths reach the OIDC configuration route."],"tags":["blazor","wasm","authentication","oidc","configuration","network","startup"],"backgroundTag":null,"analyzedSha":"3600ca084e9c8b5f4174fc5e747f4c52d2100806","analyzedAt":"2026-08-11T16:32:30.678Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}