{"record":{"id":"1e1d4a23a4d930fa","repo":"spring-projects/spring-security","slug":"unable-to-resolve-the-configuration-with-the-provi","errorCode":null,"errorMessage":"Unable to resolve the Configuration with the provided Issuer of \"\" + issuer","messagePattern":"Unable to resolve the Configuration with the provided Issuer of \"\" \\+ issuer","errorType":"exception","errorClass":"IllegalArgumentException","httpStatus":null,"severity":"error","filePath":"oauth2/oauth2-jose/src/main/java/org/springframework/security/oauth2/jwt/JwtDecoderProviderConfigurationUtils.java","lineNumber":199,"sourceCode":"\t@SuppressWarnings(\"removal\")\n\tprivate static Map<String, Object> getConfiguration(String issuer, RestOperations rest, UriComponents... uris) {\n\t\tString errorMessage = \"Unable to resolve the Configuration with the provided Issuer of \" + \"\\\"\" + issuer + \"\\\"\";\n\t\tfor (UriComponents uri : uris) {\n\t\t\ttry {\n\t\t\t\tRequestEntity<Void> request = RequestEntity.get(uri.toUriString()).build();\n\t\t\t\tResponseEntity<Map<String, Object>> response = rest.exchange(request, STRING_OBJECT_MAP);\n\t\t\t\tMap<String, Object> configuration = response.getBody();\n\t\t\t\tAssert.notNull(configuration, \"configuration must not be null\");\n\t\t\t\tAssert.isTrue(configuration.get(\"jwks_uri\") != null, \"The public JWK set URI must not be null\");\n\t\t\t\treturn configuration;\n\t\t\t}\n\t\t\tcatch (IllegalArgumentException ex) {\n\t\t\t\tthrow ex;\n\t\t\t}\n\t\t\tcatch (RuntimeException ex) {\n\t\t\t\tif (!(ex instanceof HttpClientErrorException\n\t\t\t\t\t\t&& ((HttpClientErrorException) ex).getStatusCode().is4xxClientError())) {\n\t\t\t\t\tthrow new IllegalArgumentException(errorMessage, ex);\n\t\t\t\t}\n\t\t\t\t// else try another endpoint\n\t\t\t}\n\t\t}\n\t\tthrow new IllegalArgumentException(errorMessage);\n\t}\n\n\tstatic UriComponents oidc(String issuer) {\n\t\tUriComponents uri = UriComponentsBuilder.fromUriString(issuer).build();\n\t\t// @formatter:off\n\t\treturn UriComponentsBuilder.newInstance().uriComponents(uri)\n\t\t\t\t.replacePath(uri.getPath() + OIDC_METADATA_PATH)\n\t\t\t\t.build();\n\t\t// @formatter:on\n\t}\n\n\tstatic UriComponents oidcRfc8414(String issuer) {\n\t\tUriComponents uri = UriComponentsBuilder.fromUriString(issuer).build();","sourceCodeStart":181,"sourceCodeEnd":217,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-jose/src/main/java/org/springframework/security/oauth2/jwt/JwtDecoderProviderConfigurationUtils.java#L181-L217","documentation":"Spring Security could not fetch the OIDC/OAuth2 provider configuration (/.well-known/openid-configuration or /.well-known/oauth-authorization-server) for the given issuer. After trying each well-known endpoint, a non-4xx-client-error runtime failure (network error, 5xx, connection refused) occurred, so it wraps it in this IllegalArgumentException with the issuer in the message.","triggerScenarios":"JwtDecoderProviderConfigurationUtils.getConfiguration called via getConfigurationForIssuerLocation/getConfigurationForOidcIssuerLocation; the GET to the discovery endpoint throws a RuntimeException that is not an HttpClientErrorException with a 4xx status (e.g. connection refused, DNS failure, timeout, 500 response).","commonSituations":"Typo'd issuer URL in application.yml (issuer property of spring.security.oauth2.resourceserver.jwt.issuer-uri); authorization server unreachable from the app's network; discovery endpoint returning 5xx; TLS certificate issues; the app starting before the auth server is up.","solutions":["Verify the issuer URI is correct and reachable: curl <issuer>/.well-known/openid-configuration from the host running the app.","Fix network/DNS/firewall or proxy settings so the app can reach the authorization server.","If the server starts before the provider, retry later or configure the decoder lazily / with jwk-set-uri instead of issuer-uri to skip discovery at startup.","If the provider returns 5xx on discovery, fix or check the authorization server's discovery endpoint configuration."],"exampleFix":"// before\nspring.security.oauth2.resourceserver.jwt.issuer-uri=https://auth.example.com WRONG (typo'd host)\n// after\nspring.security.oauth2.resourceserver.jwt.issuer-uri=https://auth-server.example.com","handlingStrategy":"try-catch","validationCode":"// preflight in shell\n// curl -fsS \"$ISSUER/.well-known/openid-configuration\" > /dev/null && echo reachable","typeGuard":null,"tryCatchPattern":"try { JwtDecoder d = JwtDecoders.fromIssuerLocation(issuer); }\ncatch (IllegalArgumentException e) {\n    // configuration/startup failure: check connectivity to issuer, retry or fail fast\n}","preventionTips":["curl the discovery URL from the app host during deployment health checks","Prefer jwk-set-uri configuration when discovery is not needed, removing network dependency at startup","Keep issuer URIs in one config source; validate them with a startup connectivity check"],"tags":["oidc","discovery","network","configuration"],"backgroundTag":"http-request-failed","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}