{"record":{"id":"ccc2fdf3a5b40363","repo":"spring-projects/spring-security","slug":"an-error-occurred-writing-the-oauth-2-0-access-tok","errorCode":null,"errorMessage":"An error occurred writing the OAuth 2.0 Access Token Response: ${ex.getMessage()}","messagePattern":"An error occurred writing the OAuth 2\\.0 Access Token Response: (.+?)","errorType":"http","errorClass":"HttpMessageNotWritableException","httpStatus":500,"severity":"error","filePath":"oauth2/oauth2-core/src/main/java/org/springframework/security/oauth2/core/http/converter/OAuth2AccessTokenResponseHttpMessageConverter.java","lineNumber":99,"sourceCode":"\t\t}\n\t\tcatch (Exception ex) {\n\t\t\tthrow new HttpMessageNotReadableException(\n\t\t\t\t\t\"An error occurred reading the OAuth 2.0 Access Token Response: \" + ex.getMessage(), ex,\n\t\t\t\t\tinputMessage);\n\t\t}\n\t}\n\n\t@Override\n\tprotected void writeInternal(OAuth2AccessTokenResponse tokenResponse, HttpOutputMessage outputMessage)\n\t\t\tthrows HttpMessageNotWritableException {\n\t\ttry {\n\t\t\tMap<String, Object> tokenResponseParameters = this.accessTokenResponseParametersConverter\n\t\t\t\t.convert(tokenResponse);\n\t\t\tthis.jsonMessageConverter.write(tokenResponseParameters, STRING_OBJECT_MAP.getType(),\n\t\t\t\t\tMediaType.APPLICATION_JSON, outputMessage);\n\t\t}\n\t\tcatch (Exception ex) {\n\t\t\tthrow new HttpMessageNotWritableException(\n\t\t\t\t\t\"An error occurred writing the OAuth 2.0 Access Token Response: \" + ex.getMessage(), ex);\n\t\t}\n\t}\n\n\t/**\n\t * Sets the {@link Converter} used for converting the OAuth 2.0 Access Token Response\n\t * parameters to an {@link OAuth2AccessTokenResponse}.\n\t * @param accessTokenResponseConverter the {@link Converter} used for converting to an\n\t * {@link OAuth2AccessTokenResponse}\n\t * @since 5.6\n\t */\n\tpublic final void setAccessTokenResponseConverter(\n\t\t\tConverter<Map<String, Object>, OAuth2AccessTokenResponse> accessTokenResponseConverter) {\n\t\tAssert.notNull(accessTokenResponseConverter, \"accessTokenResponseConverter cannot be null\");\n\t\tthis.accessTokenResponseConverter = accessTokenResponseConverter;\n\t}\n\n\t/**","sourceCodeStart":81,"sourceCodeEnd":117,"githubUrl":"https://github.com/spring-projects/spring-security/blob/96852e8860138a482cb13d1479573f24ff6443c6/oauth2/oauth2-core/src/main/java/org/springframework/security/oauth2/core/http/converter/OAuth2AccessTokenResponseHttpMessageConverter.java#L81-L117","documentation":"The write-side counterpart of readInternal: writeInternal serializes an OAuth2AccessTokenResponse to JSON via the configured ObjectMapper/jsonMessageConverter and wraps any serialization failure in HttpMessageNotWritableException with the cause's message. This is thrown when the token response object cannot be converted to the target parameterized map/JSON.","triggerScenarios":"Server-side token response writing (e.g. a custom token endpoint or test asserting token responses) where accessTokenResponseParametersConverter output or JSON writing fails — e.g. non-serializable values placed in additionalParameters or a misconfigured HttpMessageConverter.","commonSituations":"Custom token endpoints returning OAuth2AccessTokenResponse with unusual additionalParameters; tests using MockMvc with the converter and a broken message converter setup; ObjectMapper unable to handle a value type.","solutions":["Inspect the wrapped cause's message to find the non-serializable/invalid value","Keep additionalParameters limited to JSON-friendly types (String, Number, Boolean, collections thereof)","Verify the configured HttpMessageConverter (default MappingJackson2HttpMessageConverter) and ObjectMapper are correctly set up","When mocking in tests, ensure the converter is registered on the MockMvc message converters"],"exampleFix":null,"handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n    converter.write(tokenResponse, MediaType.APPLICATION_JSON, outputMessage);\n} catch (HttpMessageNotWritableException e) {\n    // inspect e.getCause(); check additionalParameters values are JSON-serializable\n}","preventionTips":["Keep additionalParameters limited to JSON-friendly types","Validate custom converters/ObjectMapper configuration","Test token response serialization with MockMvc before deploying"],"tags":["oauth2","http-message-conversion","serialization"],"backgroundTag":"json-serialization-failed","analyzedSha":"96852e8860138a482cb13d1479573f24ff6443c6","analyzedAt":"2026-09-10T23:25:23.477Z","contentChangedAt":"2026-09-10T23:25:23.477Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}