google-gemini/gemini-cli · error

Error: Issuer mismatch - possible OAuth mix-up attack.

Error message

Error: Issuer mismatch - possible OAuth mix-up attack.

What it means

The iss parameter in the OAuth callback does not equal the expected issuer (after issuer-normalization comparison), signaling a possible OAuth mix-up attack where the response came from a different authorization server than the one the request was sent to. The server logs the mismatch, closes, and the flow is rejected.

Solutions

  1. Correct the configured issuer URL to match the provider's actual issuer exactly
  2. Check for multiple configured providers sharing one redirect URI (mix-up scenario)
  3. Restart the flow against the intended provider
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/core/src/utils/oauth-flow.ts:297 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/82e28b352ae27aa3. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/utils/oauth-flow.ts:297

                    <p>Error: Missing issuer parameter in response.</p>
                    <p>You can close this window.</p>
                  </body>
                </html>
              `);
                server.close();
                reject(
                  new Error(
                    'Missing "iss" parameter in authorization response per RFC 9207',
                  ),
                );
                return;
              }

              if (!areIssuersEqual(iss, expectedIssuer)) {
                debugLogger.error(
                  'OAuth callback rejected: Issuer mismatch between authorization response and expected authorization server. Possible IdP mix-up attack (RFC 9207).',
                );
                res.writeHead(400, { 'Content-Type': 'text/html' });
                res.end(`
                <html>
                  <body>
                    <h1>Authentication Failed</h1>
                    <p>Error: Issuer mismatch - possible OAuth mix-up attack.</p>
                    <p>You can close this window.</p>
                  </body>
                </html>
              `);
                server.close();
                reject(
                  new Error(
                    'Issuer mismatch in authorization response - possible OAuth mix-up attack',
                  ),
                );
                return;
              }
              debugLogger.debug(

View on GitHub (pinned to 6a466a7e2f)