spring-projects/spring-security · error · IllegalArgumentException
Invalid Authorization Grant Type
Error message
Invalid Authorization Grant Type (${grantType}) for Client Registration with Id: ${registrationId} What it means
Reactive counterpart of the servlet resolver: DefaultServerOAuth2AuthorizationRequestResolver.getBuilder (called from getClientRegistrations) throws IllegalArgumentException when the ClientRegistration's AuthorizationGrantType is not authorization_code (or JWT bearer), because WebFlux OAuth2 login only supports the browser redirect flow.
Solutions
- Set the registration to authorization_code or remove the grant-type field to use the default
- Fetch client_credentials tokens programmatically via WebClient + ServerOAuth2AuthorizedClientExchangeFilterFunction with a ClientProvider, not via the login redirect
- Implement a custom ServerOAuth2AuthorizationRequestResolver if a non-standard grant is genuinely needed
Example fix
// before spring.security.oauth2.client.registration.myclient.authorization-grant-type: client_credentials // after spring.security.oauth2.client.registration.myclient.authorization-grant-type: authorization_code
Defensive patterns
Strategy: validation
Validate before calling
if (!AuthorizationGrantType.AUTHORIZATION_CODE.equals(registration.getAuthorizationGrantType())) {
throw new IllegalStateException("Reactive OAuth2 login requires authorization_code grant for " + registration.getRegistrationId());
} Prevention
- Omit grant-type in reactive registration config so it defaults to authorization_code
- Handle client_credentials tokens via ServerOAuth2AuthorizedClientExchangeFilterFunction, not login redirects
- Audit grant-type strings for typos
When it happens
Trigger: A reactive spring.security.oauth2.client.registration entry declares grant-type client_credentials (or another non-redirect grant) and the /oauth2/authorization/{registrationId} endpoint is hit.
Common situations: Reusing a servlet client_credentials registration in a WebFlux app; YAML grant-type typos; attempting OAuth2 login with token/credential flows that require programmatic token retrieval instead.
Understand the failure class
Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.
Related errors
- Invalid Authorization Grant Type
- invalid_token
- missing_user_info_uri
- missing_user_name_attribute
- An error occurred reading the OAuth 2.0 Client…
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/19992deb5e3ad7f0.
Report an issue: GitHub.
Appendix: source
Thrown at oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/server/DefaultServerOAuth2AuthorizationRequestResolver.java:210
.attributes((attrs) ->
attrs.put(OAuth2ParameterNames.REGISTRATION_ID, clientRegistration.getRegistrationId()));
// @formatter:on
if (!CollectionUtils.isEmpty(clientRegistration.getScopes())
&& clientRegistration.getScopes().contains(OidcScopes.OPENID)) {
// Section 3.1.2.1 Authentication Request -
// https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest
// scope
// REQUIRED. OpenID Connect requests MUST contain the "openid" scope
// value.
applyNonce(builder);
}
if (ClientAuthenticationMethod.NONE.equals(clientRegistration.getClientAuthenticationMethod())
|| clientRegistration.getClientSettings().isRequireProofKey()) {
DEFAULT_PKCE_APPLIER.accept(builder);
}
return builder;
}
throw new IllegalArgumentException(
"Invalid Authorization Grant Type (" + clientRegistration.getAuthorizationGrantType().getValue()
+ ") for Client Registration with Id: " + clientRegistration.getRegistrationId());
}
/**
* Expands the {@link ClientRegistration#getRedirectUri()} with following provided
* variables:<br/>
* - baseUrl (e.g. https://localhost/app) <br/>
* - baseScheme (e.g. https) <br/>
* - baseHost (e.g. localhost) <br/>
* - basePort (e.g. :8080) <br/>
* - basePath (e.g. /app) <br/>
* - registrationId (e.g. google) <br/>
* - action (e.g. login) <br/>
* <p/>
* Null variables are provided as empty strings.
* <p/>
* Default redirectUri is:View on GitHub (pinned to 96852e8860)