dotnet/aspnetcore · error · Error
Could not load settings from
Error message
Could not load settings from '${settings.configurationEndpoint}' What it means
In the OIDC-based Blazor WebAssembly Authentication service (RemoteAuthentication / OidcAuthorizeService), when configured with API-authorization settings it fetches the OIDC discovery document from settings.configurationEndpoint to build the UserManager settings. If the fetch returns a non-OK HTTP status (!response.ok), the configuration cannot be loaded and the service throws, halting user-manager creation.
Solutions
- Open the configurationEndpoint URL directly in a browser/devtools to see the actual status and message (404, 401, etc.).
- Ensure server-side AddApiAuthorization / AddOidc is registered and the SPA client name matches {ApplicationName} used by the client.
- Check that the configurationEndpoint URL is correct relative to the app's base href (subdirectory hosting often needs adjusting).
- Verify network/CORS/proxy reachability to the endpoint; confirm no auth requirement on the configuration route.
Example fix
// before: misconfigured endpoint returning 404
const settings = { configurationEndpoint: '/_configuration/WrongName' };
// after: match the server-registered application name and base path
const settings = { configurationEndpoint: `/_configuration/${appName}` };
// and on the server:
services.AddApiAuthorization(options => options.ProviderOptions.ConfigurationEndpoint = $"/_configuration/{appName}"); Defensive patterns
Strategy: validation
Validate before calling
// Before constructing the UserManager, validate the configuration endpoint is reachable
async function configurationReachable(url: string): Promise<boolean> {
try {
const r = await fetch(url);
return r.ok;
} catch { return false; }
}
if (!(await configurationReachable(settings.configurationEndpoint))) {
// surface a clear startup error with the URL and status
throw new Error(`OIDC configuration endpoint not reachable: ${settings.configurationEndpoint}`);
} Try / catch
try {
await createUserManager(settings);
} catch (e) {
if (/Could not load settings/i.test((e as Error).message)) {
// log the endpoint URL, check AddApiAuthorization registration, then guide the user
console.error('OIDC config load failed for', settings.configurationEndpoint);
}
throw e;
} Prevention
- Verify AddApiAuthorization / AddOidc is registered server-side and the app name matches.
- Open the configurationEndpoint URL in a browser to inspect the actual status.
- Account for subdirectory hosting when forming the configurationEndpoint URL.
- Ensure network/CORS/proxy paths reach the OIDC configuration route.
When it happens
Trigger: Thrown at line 491 inside createUserManager when isApiAuthorizationSettings(settings) is true and the fetch to settings.configurationEndpoint returns a non-2xx status. Happens at startup when the OIDC config endpoint is unreachable or returns an error.
Common situations: The application's OIDC configuration endpoint (typically /_configuration/{AppName}) returns 404 because server-side AddOidc / API authorization was not wired correctly; the endpoint requires auth and returns 401/403; a network/proxy/CORS issue blocks the request; the SPA is hosted separately from the API and the configuration URL is misconfigured; running in an environment where the host base path differs (subdirectory hosting).
Related errors
- Failed to retrieve token, no account found.
- Scopes not granted.
- The server responded with status
- ' ' is flagged with SingleDelivery, but the selected…
- Authentication refreshBeforeExpirationInMilliseconds must…
AI-assisted analysis of dotnet/aspnetcore@3600ca084e (2026-08-11).
Data as JSON: /api/errors/1a277a5c846c42df.
Report an issue: GitHub.
Appendix: source
Thrown at src/Components/WebAssembly/WebAssembly.Authentication/src/Interop/AuthenticationService.ts:491
}
public static async completeSignOut(url: string) {
let operation = this._pendingOperations[url];
if (!operation) {
operation = AuthenticationService.instance.completeSignOut(url);
await operation;
delete this._pendingOperations[url];
}
return operation;
}
private static async createUserManager(settings: OidcAuthorizeServiceSettings): Promise<UserManager> {
let finalSettings: UserManagerSettings;
if (isApiAuthorizationSettings(settings)) {
const response = await fetch(settings.configurationEndpoint);
if (!response.ok) {
throw new Error(`Could not load settings from '${settings.configurationEndpoint}'`);
}
const downloadedSettings = await response.json();
finalSettings = downloadedSettings;
} else {
if (!settings.scope) {
settings.scope = settings.defaultScopes.join(' ');
}
if (settings.response_type === null) {
// If the response type is not set, it gets serialized as null. OIDC-client behaves differently than when the value is undefined, so we explicitly check for a null value and remove the property instead.
delete settings.response_type;
}
finalSettings = settings;
}
View on GitHub (pinned to 3600ca084e)