google-gemini/gemini-cli · error

Error: Missing issuer parameter in response.

Error message

Error: Missing issuer parameter in response.

What it means

RFC 9207 issuer identification is enabled (expectedIssuer set) but the authorization response omitted the iss parameter. The check fails closed: absence of the issuer is treated as a mix-up-attack risk, the server closes, and the flow is rejected with a missing-iss error.

Solutions

  1. Verify the OAuth provider supports RFC 9207 iss in authorization responses
  2. Confirm the expected issuer configuration matches the provider's actual issuer URL
  3. Disable the issuer check only if the provider is known not to support RFC 9207
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/core/src/utils/oauth-flow.ts:274 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/2ec57327b935996c. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/utils/oauth-flow.ts:274

            if (state !== expectedState) {
              debugLogger.error(
                `OAuth callback state mismatch: received state "${state}", expected "${expectedState}". Possible CSRF attack.`,
              );
              res.writeHead(400);
              res.end('Invalid state parameter');
              server.close();
              reject(new Error('State mismatch - possible CSRF attack'));
              return;
            }

            // RFC 9207 Authorization Server Issuer Identification check
            if (expectedIssuer) {
              // Fail-closed: if an issuer was expected, the response MUST include it
              if (!iss) {
                debugLogger.error(
                  'OAuth callback rejected: Missing required "iss" parameter when an expected issuer is configured. Possible IdP mix-up attack (RFC 9207).',
                );
                res.writeHead(400, { 'Content-Type': 'text/html' });
                res.end(`
                <html>
                  <body>
                    <h1>Authentication Failed</h1>
                    <p>Error: Missing issuer parameter in response.</p>
                    <p>You can close this window.</p>
                  </body>
                </html>
              `);
                server.close();
                reject(
                  new Error(
                    'Missing "iss" parameter in authorization response per RFC 9207',
                  ),
                );
                return;
              }

View on GitHub (pinned to 6a466a7e2f)