spring-projects/spring-security · error · OAuth2AuthenticationException
client_registration_not_found
client_registration_not_found
Error message
Client Registration not found with Id: ${registrationId} What it means
After loading the stored authorization request, the filter reads its registration_id attribute and looks up the ClientRegistration in the ClientRegistrationRepository. This error means the registration id recorded in the authorization request no longer resolves to a registered client.
Solutions
- Keep registration ids stable across deploys, or invalidate old sessions on redeploy
- Confirm the registration id used in the authorization request exists in your ClientRegistrationRepository (check InMemoryClientRegistrationRepository contents)
- Restart the login flow so a fresh authorization request referencing a valid registration is created
Defensive patterns
Strategy: validation
Validate before calling
ClientRegistration cr = clientRegistrationRepository.findByRegistrationId(id);
if (cr == null) {
throw new IllegalStateException("Unknown registration id: " + id);
} Try / catch
catch (OAuth2AuthenticationException e) {
if ("client_registration_not_found".equals(e.getError().getErrorCode())) {
// clear session and restart the login flow
}
} Prevention
- Keep registration ids stable across deployments
- Invalidate/rotate sessions when client registration config changes
- Verify InMemoryClientRegistrationRepository contents match configured ids
When it happens
Trigger: The registration was removed or renamed in configuration between the time the login flow started and the callback arrived (stale session), or the InMemoryClientRegistrationRepository was rebuilt/redeployed with a different id.
Common situations: Renaming spring.security.oauth2.client.registration.<id> during a rolling redeploy while users hold active sessions; dynamically registered clients being evicted; typo in repository setup when building registrations programmatically.
Understand the failure class
Background: 'Could not be found', 'does not exist', 'not found in database': the resource-not-found family when an ID, slug, key, or URI lookup comes back empty — this error's family across 20 libraries.
Related errors
- Invalid Authorization Grant Type
- Invalid Client Registration with Id
- missing_user_info_uri
- missing_user_info_uri
- missing_user_name_attribute
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/03cff46323608b64.
Report an issue: GitHub.
Appendix: source
Thrown at oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/OAuth2LoginAuthenticationFilter.java:186
throws AuthenticationException {
MultiValueMap<String, String> params = OAuth2AuthorizationResponseUtils.toMultiMap(request.getParameterMap());
if (!OAuth2AuthorizationResponseUtils.isAuthorizationResponse(params)) {
OAuth2Error oauth2Error = new OAuth2Error(OAuth2ErrorCodes.INVALID_REQUEST);
throw new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString());
}
OAuth2AuthorizationRequest authorizationRequest = this.authorizationRequestRepository
.removeAuthorizationRequest(request, response);
if (authorizationRequest == null) {
OAuth2Error oauth2Error = new OAuth2Error(AUTHORIZATION_REQUEST_NOT_FOUND_ERROR_CODE);
throw new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString());
}
String registrationId = authorizationRequest.getAttribute(OAuth2ParameterNames.REGISTRATION_ID);
Assert.hasText(registrationId, "registrationId cannot be empty");
ClientRegistration clientRegistration = this.clientRegistrationRepository.findByRegistrationId(registrationId);
if (clientRegistration == null) {
OAuth2Error oauth2Error = new OAuth2Error(CLIENT_REGISTRATION_NOT_FOUND_ERROR_CODE,
"Client Registration not found with Id: " + registrationId, null);
throw new OAuth2AuthenticationException(oauth2Error, oauth2Error.toString());
}
// @formatter:off
String redirectUri = UriComponentsBuilder.fromUriString(UrlUtils.buildFullRequestUrl(request))
.replaceQuery(null)
.build()
.toUriString();
// @formatter:on
OAuth2AuthorizationResponse authorizationResponse = OAuth2AuthorizationResponseUtils.convert(params,
redirectUri);
Object authenticationDetails = this.authenticationDetailsSource.buildDetails(request);
OAuth2LoginAuthenticationToken authenticationRequest = new OAuth2LoginAuthenticationToken(clientRegistration,
new OAuth2AuthorizationExchange(authorizationRequest, authorizationResponse));
authenticationRequest.setDetails(authenticationDetails);
OAuth2LoginAuthenticationToken authenticationResult = (OAuth2LoginAuthenticationToken) this
.getAuthenticationManager()
.authenticate(authenticationRequest);
OAuth2AuthenticationToken oauth2Authentication = this.authenticationResultConverter
.convert(authenticationResult);View on GitHub (pinned to 96852e8860)