spring-projects/spring-security · error · IllegalArgumentException

Invalid Authorization Grant Type

Error message

Invalid Authorization Grant Type (${grantType}) for Client Registration with Id: ${registrationId}

What it means

Reactive counterpart of the servlet resolver: DefaultServerOAuth2AuthorizationRequestResolver.getBuilder (called from getClientRegistrations) throws IllegalArgumentException when the ClientRegistration's AuthorizationGrantType is not authorization_code (or JWT bearer), because WebFlux OAuth2 login only supports the browser redirect flow.

Solutions

  1. Set the registration to authorization_code or remove the grant-type field to use the default
  2. Fetch client_credentials tokens programmatically via WebClient + ServerOAuth2AuthorizedClientExchangeFilterFunction with a ClientProvider, not via the login redirect
  3. Implement a custom ServerOAuth2AuthorizationRequestResolver if a non-standard grant is genuinely needed

Example fix

// before
spring.security.oauth2.client.registration.myclient.authorization-grant-type: client_credentials
// after
spring.security.oauth2.client.registration.myclient.authorization-grant-type: authorization_code
Defensive patterns

Strategy: validation

Validate before calling

if (!AuthorizationGrantType.AUTHORIZATION_CODE.equals(registration.getAuthorizationGrantType())) {
    throw new IllegalStateException("Reactive OAuth2 login requires authorization_code grant for " + registration.getRegistrationId());
}

Prevention

When it happens

Trigger: A reactive spring.security.oauth2.client.registration entry declares grant-type client_credentials (or another non-redirect grant) and the /oauth2/authorization/{registrationId} endpoint is hit.

Common situations: Reusing a servlet client_credentials registration in a WebFlux app; YAML grant-type typos; attempting OAuth2 login with token/credential flows that require programmatic token retrieval instead.

Understand the failure class

Background: Invalid enum value errors: "Unknown type", "Invalid scope", "must be one of" — when a string is not on the library's allowed list — this error's family across 23 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/19992deb5e3ad7f0. Report an issue: GitHub.

Appendix: source

Thrown at oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/web/server/DefaultServerOAuth2AuthorizationRequestResolver.java:210

					.attributes((attrs) ->
							attrs.put(OAuth2ParameterNames.REGISTRATION_ID, clientRegistration.getRegistrationId()));
			// @formatter:on
			if (!CollectionUtils.isEmpty(clientRegistration.getScopes())
					&& clientRegistration.getScopes().contains(OidcScopes.OPENID)) {
				// Section 3.1.2.1 Authentication Request -
				// https://openid.net/specs/openid-connect-core-1_0.html#AuthRequest
				// scope
				// REQUIRED. OpenID Connect requests MUST contain the "openid" scope
				// value.
				applyNonce(builder);
			}
			if (ClientAuthenticationMethod.NONE.equals(clientRegistration.getClientAuthenticationMethod())
					|| clientRegistration.getClientSettings().isRequireProofKey()) {
				DEFAULT_PKCE_APPLIER.accept(builder);
			}
			return builder;
		}
		throw new IllegalArgumentException(
				"Invalid Authorization Grant Type (" + clientRegistration.getAuthorizationGrantType().getValue()
						+ ") for Client Registration with Id: " + clientRegistration.getRegistrationId());
	}

	/**
	 * Expands the {@link ClientRegistration#getRedirectUri()} with following provided
	 * variables:<br/>
	 * - baseUrl (e.g. https://localhost/app) <br/>
	 * - baseScheme (e.g. https) <br/>
	 * - baseHost (e.g. localhost) <br/>
	 * - basePort (e.g. :8080) <br/>
	 * - basePath (e.g. /app) <br/>
	 * - registrationId (e.g. google) <br/>
	 * - action (e.g. login) <br/>
	 * <p/>
	 * Null variables are provided as empty strings.
	 * <p/>
	 * Default redirectUri is:

View on GitHub (pinned to 96852e8860)