google-gemini/gemini-cli · error

Invalid state parameter

Error message

Invalid state parameter

What it means

The OAuth callback carried a state parameter that does not match the expected state generated at flow start, indicating a possible CSRF/replay attack. The server responds 400, logs the mismatch, closes, and rejects with a state-mismatch error. This is a security guard on the authorization response.

Solutions

  1. Restart the OAuth flow to generate a fresh state
  2. Ensure only one login flow runs at a time (stale callback from an earlier attempt)
  3. Verify no proxy or extension alters query parameters
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/core/src/utils/oauth-flow.ts:260 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/a5865ee4206a965c. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/utils/oauth-flow.ts:260

              server.close();
              reject(new Error(`OAuth error: ${error}`));
              return;
            }

            if (!code || !state) {
              debugLogger.warn(
                'OAuth callback rejected: Missing code or state parameter.',
              );
              res.writeHead(400);
              res.end('Missing code or state parameter');
              return;
            }

            if (state !== expectedState) {
              debugLogger.error(
                `OAuth callback state mismatch: received state "${state}", expected "${expectedState}". Possible CSRF attack.`,
              );
              res.writeHead(400);
              res.end('Invalid state parameter');
              server.close();
              reject(new Error('State mismatch - possible CSRF attack'));
              return;
            }

            // RFC 9207 Authorization Server Issuer Identification check
            if (expectedIssuer) {
              // Fail-closed: if an issuer was expected, the response MUST include it
              if (!iss) {
                debugLogger.error(
                  'OAuth callback rejected: Missing required "iss" parameter when an expected issuer is configured. Possible IdP mix-up attack (RFC 9207).',
                );
                res.writeHead(400, { 'Content-Type': 'text/html' });
                res.end(`
                <html>
                  <body>
                    <h1>Authentication Failed</h1>

View on GitHub (pinned to 6a466a7e2f)