spring-projects/spring-security · error · IllegalArgumentException

Unable to resolve Configuration with the provided Issuer of

Error message

Unable to resolve Configuration with the provided Issuer of "${issuer}", errors: ${errors}

What it means

Variant of the discovery failure in ClientRegistrations.getBuilder: configuration was fetched but multiple endpoints/parse attempts failed, and the collected per-endpoint errors are appended to the message ('..., errors: [...]') to explain why resolution failed.

Solutions

  1. Read the appended errors list — it names each endpoint's underlying failure (status, parse exception) and fix that root cause first.
  2. curl the discovery URLs and confirm they return valid JSON (an HTML login page means auth/redirect is intercepting the request).
  3. Whitelist/exempt the discovery path from gateway authentication, or supply a cookie/proxy config so the request reaches the metadata handler.
  4. Fall back to a manually built ClientRegistration if discovery cannot be repaired on the provider side.

Example fix

// before
ClientRegistrations.fromIssuerLocation("https://idp"); // gateway returns HTML login page -> parse errors
// after
// allowlist /.well-known/* on the gateway, then retry:
ClientRegistrations.fromIssuerLocation("https://idp");
Defensive patterns

Strategy: try-catch

Validate before calling

// fetch and JSON-parse discovery yourself to surface the real error
String body = rest.getForEntity(issuer + "/.well-known/openid-configuration", String.class).getBody();
new com.fasterxml.jackson.databind.ObjectMapper().readTree(body); // throws with a precise parse error

Try / catch

try { ClientRegistrations.fromIssuerLocation(issuer); } catch (IllegalArgumentException e) { log.error("Discovery failed: {}", e.getMessage(), e); /* inspect ', errors:' appendix */ throw e; }

Prevention

When it happens

Trigger: fromIssuerLocation(issuer) trying both openid-configuration and oauth-authorization-server URLs; both attempts fail with runtime exceptions whose messages are accumulated into the errors list, producing this richer IllegalArgumentException.

Common situations: Discovery endpoint returns 200 but with HTML (login page/redirect) instead of JSON; server returns malformed JSON; intermittent upstream 500s recorded per attempt; misconfigured reverse proxy.

Understand the failure class

Background: "Invalid JSON response" and "Failed to parse response" errors: when an API answers 200 but the body isn't the JSON your library expected — this error's family across 28 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/349fc9371c1c0401. Report an issue: GitHub.

Appendix: source

Thrown at oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/registration/ClientRegistrations.java:294

			try {
				return supplier.get();
			}
			catch (HttpClientErrorException ex) {
				if (!ex.getStatusCode().is4xxClientError()) {
					throw ex;
				}
				errors.add(ex.getMessage());
				// else try another endpoint
			}
			catch (IllegalArgumentException | IllegalStateException ex) {
				throw ex;
			}
			catch (RuntimeException ex) {
				throw new IllegalArgumentException(errorMessage, ex);
			}
		}
		if (!errors.isEmpty()) {
			throw new IllegalArgumentException(errorMessage + ", errors: " + errors);
		}
		throw new IllegalArgumentException(errorMessage);
	}

	private static <T> T parseInput(Map<String, Object> body, ThrowingFunction<JSONObject, T, ParseException> parser) {
		try {
			return parse(body, parser);
		}
		catch (RuntimeException ex) {
			throw new IllegalArgumentException(ex);
		}
	}

	private static <T> T parse(Map<String, Object> body, ThrowingFunction<JSONObject, T, ParseException> parser) {
		try {
			return parser.apply(new JSONObject(body));
		}
		catch (ParseException ex) {

View on GitHub (pinned to 96852e8860)