google-gemini/gemini-cli · error
Missing code or state parameter
Error message
Missing code or state parameter
What it means
The OAuth callback server received a redirect request missing the required code or state query parameter, so the authorization response is malformed and the flow is rejected with a 400. A debug log records the rejection before the plain-text response.
Solutions
- Retry the login flow to get a fresh, well-formed authorization response
- Verify the provider redirect URI configuration
- Check for browser extensions or proxies stripping query parameters
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at packages/core/src/utils/oauth-flow.ts:251 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16).
Data as JSON: /api/errors/b405ec1c1766f9a5.
Report an issue: GitHub.
Appendix: source
Thrown at packages/core/src/utils/oauth-flow.ts:251
<html>
<body>
<h1>Authentication Failed</h1>
<p>Error: ${error.replace(/</g, '<').replace(/>/g, '>')}</p>
<p>${(url.searchParams.get('error_description') || '').replace(/</g, '<').replace(/>/g, '>')}</p>
<p>You can close this window.</p>
</body>
</html>
`);
server.close();
reject(new Error(`OAuth error: ${error}`));
return;
}
if (!code || !state) {
debugLogger.warn(
'OAuth callback rejected: Missing code or state parameter.',
);
res.writeHead(400);
res.end('Missing code or state parameter');
return;
}
if (state !== expectedState) {
debugLogger.error(
`OAuth callback state mismatch: received state "${state}", expected "${expectedState}". Possible CSRF attack.`,
);
res.writeHead(400);
res.end('Invalid state parameter');
server.close();
reject(new Error('State mismatch - possible CSRF attack'));
return;
}
// RFC 9207 Authorization Server Issuer Identification check
if (expectedIssuer) {
// Fail-closed: if an issuer was expected, the response MUST include itView on GitHub (pinned to 6a466a7e2f)