google-gemini/gemini-cli · error
Error: Issuer mismatch - possible OAuth mix-up attack.
Error message
Error: Issuer mismatch - possible OAuth mix-up attack.
What it means
The iss parameter in the OAuth callback does not equal the expected issuer (after issuer-normalization comparison), signaling a possible OAuth mix-up attack where the response came from a different authorization server than the one the request was sent to. The server logs the mismatch, closes, and the flow is rejected.
Solutions
- Correct the configured issuer URL to match the provider's actual issuer exactly
- Check for multiple configured providers sharing one redirect URI (mix-up scenario)
- Restart the flow against the intended provider
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at packages/core/src/utils/oauth-flow.ts:297 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/82e28b352ae27aa3.
Report an issue: GitHub.
Appendix: source
Thrown at packages/core/src/utils/oauth-flow.ts:297
<p>Error: Missing issuer parameter in response.</p>
<p>You can close this window.</p>
</body>
</html>
`);
server.close();
reject(
new Error(
'Missing "iss" parameter in authorization response per RFC 9207',
),
);
return;
}
if (!areIssuersEqual(iss, expectedIssuer)) {
debugLogger.error(
'OAuth callback rejected: Issuer mismatch between authorization response and expected authorization server. Possible IdP mix-up attack (RFC 9207).',
);
res.writeHead(400, { 'Content-Type': 'text/html' });
res.end(`
<html>
<body>
<h1>Authentication Failed</h1>
<p>Error: Issuer mismatch - possible OAuth mix-up attack.</p>
<p>You can close this window.</p>
</body>
</html>
`);
server.close();
reject(
new Error(
'Issuer mismatch in authorization response - possible OAuth mix-up attack',
),
);
return;
}
debugLogger.debug(View on GitHub (pinned to 6a466a7e2f)