{"record":{"id":"99e7ceb469fcfdd6","repo":"spring-projects/spring-security","slug":"an-error-occurred-reading-the-oauth-2-0-access-tok","errorCode":null,"errorMessage":"An error occurred reading the OAuth 2.0 Access Token Response: ${ex.getMessage()}","messagePattern":"An error occurred reading the OAuth 2\\.0 Access Token Response: (.+?)","errorType":"http","errorClass":"HttpMessageNotReadableException","httpStatus":400,"severity":"error","filePath":"oauth2/oauth2-core/src/main/java/org/springframework/security/oauth2/core/http/converter/OAuth2AccessTokenResponseHttpMessageConverter.java","lineNumber":83,"sourceCode":"\t\tthis.jsonMessageConverter = converter;\n\t}\n\n\t@Override\n\tprotected boolean supports(Class<?> clazz) {\n\t\treturn OAuth2AccessTokenResponse.class.isAssignableFrom(clazz);\n\t}\n\n\t@Override\n\t@SuppressWarnings(\"unchecked\")\n\tprotected OAuth2AccessTokenResponse readInternal(Class<? extends OAuth2AccessTokenResponse> clazz,\n\t\t\tHttpInputMessage inputMessage) throws HttpMessageNotReadableException {\n\t\ttry {\n\t\t\tMap<String, Object> tokenResponseParameters = (Map<String, Object>) this.jsonMessageConverter\n\t\t\t\t.read(STRING_OBJECT_MAP.getType(), null, inputMessage);\n\t\t\treturn this.accessTokenResponseConverter.convert(tokenResponseParameters);\n\t\t}\n\t\tcatch (Exception ex) {\n\t\t\tthrow new HttpMessageNotReadableException(\n\t\t\t\t\t\"An error occurred reading the OAuth 2.0 Access Token Response: \" + ex.getMessage(), ex,\n\t\t\t\t\tinputMessage);\n\t\t}\n\t}\n\n\t@Override\n\tprotected void writeInternal(OAuth2AccessTokenResponse tokenResponse, HttpOutputMessage outputMessage)\n\t\t\tthrows HttpMessageNotWritableException {\n\t\ttry {\n\t\t\tMap<String, Object> tokenResponseParameters = this.accessTokenResponseParametersConverter\n\t\t\t\t.convert(tokenResponse);\n\t\t\tthis.jsonMessageConverter.write(tokenResponseParameters, STRING_OBJECT_MAP.getType(),\n\t\t\t\t\tMediaType.APPLICATION_JSON, outputMessage);\n\t\t}\n\t\tcatch (Exception ex) {\n\t\t\tthrow new HttpMessageNotWritableException(\n\t\t\t\t\t\"An error occurred writing the OAuth 2.0 Access Token Response: \" + ex.getMessage(), ex);\n\t\t}","sourceCodeStart":65,"sourceCodeEnd":101,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-core/src/main/java/org/springframework/security/oauth2/core/http/converter/OAuth2AccessTokenResponseHttpMessageConverter.java#L65-L101","documentation":"OAuth2AccessTokenResponseHttpMessageConverter.readInternal wraps any failure while reading/parsing the token endpoint HTTP response into an HttpMessageNotReadableException whose message includes the original exception message. Typical underlying causes are JSON parse failures or the converter rejecting the payload (e.g. missing access_token).","triggerScenarios":"Token endpoint returns non-JSON (HTML login/error page, empty body), malformed JSON, or a JSON body the DefaultMapOAuth2AccessTokenResponseConverter rejects — then readInternal converts the exception.","commonSituations":"Wrong token-uri pointing to an HTML page; gateway/SSO intercepting and returning an error page; provider sending text/plain content type the JSON converter refuses; missing access_token in an otherwise-200 response.","solutions":["Log/inspect the underlying exception and raw body: enable wire-level logging for the token request to see what the server actually returned","Verify the token-uri points at the JSON token endpoint and that no proxy/SSO intercepts the call","Check the response Content-Type is application/json and the provider returns a spec-compliant body","If the provider's body deviates (e.g. errors with 200), plug in a custom access token response converter"],"exampleFix":"// before\n# token-uri pointing at authorize endpoint\nprovider.myidp.token-uri: https://idp.example.com/authorize\n// after\nprovider.myidp.token-uri: https://idp.example.com/oauth2/token","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n    OAuth2AccessTokenResponse r = converter.convert(inputMessage);\n} catch (HttpMessageNotReadableException e) {\n    // log e.getCause() and the raw body to see what the token endpoint returned\n}","preventionTips":["Verify token-uri points to the JSON token endpoint, not the authorize/login page","Ensure response Content-Type is application/json","Log the raw token response body when debugging","Add a custom access token response converter for non-conforming providers"],"tags":["oauth2","http-message-conversion","token-response","parsing"],"backgroundTag":"invalid-json-response","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}