google-gemini/gemini-cli · error
Error: Missing issuer parameter in response.
Error message
Error: Missing issuer parameter in response.
What it means
RFC 9207 issuer identification is enabled (expectedIssuer set) but the authorization response omitted the iss parameter. The check fails closed: absence of the issuer is treated as a mix-up-attack risk, the server closes, and the flow is rejected with a missing-iss error.
Solutions
- Verify the OAuth provider supports RFC 9207 iss in authorization responses
- Confirm the expected issuer configuration matches the provider's actual issuer URL
- Disable the issuer check only if the provider is known not to support RFC 9207
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at packages/core/src/utils/oauth-flow.ts:274 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/2ec57327b935996c.
Report an issue: GitHub.
Appendix: source
Thrown at packages/core/src/utils/oauth-flow.ts:274
if (state !== expectedState) {
debugLogger.error(
`OAuth callback state mismatch: received state "${state}", expected "${expectedState}". Possible CSRF attack.`,
);
res.writeHead(400);
res.end('Invalid state parameter');
server.close();
reject(new Error('State mismatch - possible CSRF attack'));
return;
}
// RFC 9207 Authorization Server Issuer Identification check
if (expectedIssuer) {
// Fail-closed: if an issuer was expected, the response MUST include it
if (!iss) {
debugLogger.error(
'OAuth callback rejected: Missing required "iss" parameter when an expected issuer is configured. Possible IdP mix-up attack (RFC 9207).',
);
res.writeHead(400, { 'Content-Type': 'text/html' });
res.end(`
<html>
<body>
<h1>Authentication Failed</h1>
<p>Error: Missing issuer parameter in response.</p>
<p>You can close this window.</p>
</body>
</html>
`);
server.close();
reject(
new Error(
'Missing "iss" parameter in authorization response per RFC 9207',
),
);
return;
}
View on GitHub (pinned to 6a466a7e2f)