google-gemini/gemini-cli · error

Missing code or state parameter

Error message

Missing code or state parameter

What it means

The OAuth callback server received a redirect request missing the required code or state query parameter, so the authorization response is malformed and the flow is rejected with a 400. A debug log records the rejection before the plain-text response.

Solutions

  1. Retry the login flow to get a fresh, well-formed authorization response
  2. Verify the provider redirect URI configuration
  3. Check for browser extensions or proxies stripping query parameters
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/core/src/utils/oauth-flow.ts:251 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of google-gemini/gemini-cli@6a466a7e2f (2026-09-16). Data as JSON: /api/errors/b405ec1c1766f9a5. Report an issue: GitHub.

Appendix: source

Thrown at packages/core/src/utils/oauth-flow.ts:251

              <html>
                <body>
                  <h1>Authentication Failed</h1>
                  <p>Error: ${error.replace(/</g, '&lt;').replace(/>/g, '&gt;')}</p>
                  <p>${(url.searchParams.get('error_description') || '').replace(/</g, '&lt;').replace(/>/g, '&gt;')}</p>
                  <p>You can close this window.</p>
                </body>
              </html>
            `);
              server.close();
              reject(new Error(`OAuth error: ${error}`));
              return;
            }

            if (!code || !state) {
              debugLogger.warn(
                'OAuth callback rejected: Missing code or state parameter.',
              );
              res.writeHead(400);
              res.end('Missing code or state parameter');
              return;
            }

            if (state !== expectedState) {
              debugLogger.error(
                `OAuth callback state mismatch: received state "${state}", expected "${expectedState}". Possible CSRF attack.`,
              );
              res.writeHead(400);
              res.end('Invalid state parameter');
              server.close();
              reject(new Error('State mismatch - possible CSRF attack'));
              return;
            }

            // RFC 9207 Authorization Server Issuer Identification check
            if (expectedIssuer) {
              // Fail-closed: if an issuer was expected, the response MUST include it

View on GitHub (pinned to 6a466a7e2f)