spring-projects/spring-security · error · IllegalArgumentException
Unable to resolve Configuration with the provided Issuer of
Error message
Unable to resolve Configuration with the provided Issuer of "${issuer}", errors: ${errors} What it means
Variant of the discovery failure in ClientRegistrations.getBuilder: configuration was fetched but multiple endpoints/parse attempts failed, and the collected per-endpoint errors are appended to the message ('..., errors: [...]') to explain why resolution failed.
Solutions
- Read the appended errors list — it names each endpoint's underlying failure (status, parse exception) and fix that root cause first.
- curl the discovery URLs and confirm they return valid JSON (an HTML login page means auth/redirect is intercepting the request).
- Whitelist/exempt the discovery path from gateway authentication, or supply a cookie/proxy config so the request reaches the metadata handler.
- Fall back to a manually built ClientRegistration if discovery cannot be repaired on the provider side.
Example fix
// before
ClientRegistrations.fromIssuerLocation("https://idp"); // gateway returns HTML login page -> parse errors
// after
// allowlist /.well-known/* on the gateway, then retry:
ClientRegistrations.fromIssuerLocation("https://idp"); Defensive patterns
Strategy: try-catch
Validate before calling
// fetch and JSON-parse discovery yourself to surface the real error String body = rest.getForEntity(issuer + "/.well-known/openid-configuration", String.class).getBody(); new com.fasterxml.jackson.databind.ObjectMapper().readTree(body); // throws with a precise parse error
Try / catch
try { ClientRegistrations.fromIssuerLocation(issuer); } catch (IllegalArgumentException e) { log.error("Discovery failed: {}", e.getMessage(), e); /* inspect ', errors:' appendix */ throw e; } Prevention
- Check the ', errors:' suffix in the message for per-endpoint root causes
- Ensure discovery URLs return application/json (no HTML login/redirect pages)
- Warm up discovery during deployment health checks
When it happens
Trigger: fromIssuerLocation(issuer) trying both openid-configuration and oauth-authorization-server URLs; both attempts fail with runtime exceptions whose messages are accumulated into the errors list, producing this richer IllegalArgumentException.
Common situations: Discovery endpoint returns 200 but with HTML (login page/redirect) instead of JSON; server returns malformed JSON; intermittent upstream 500s recorded per attempt; misconfigured reverse proxy.
Understand the failure class
Background: "Invalid JSON response" and "Failed to parse response" errors: when an API answers 200 but the body isn't the JSON your library expected — this error's family across 28 libraries.
Related errors
- Unable to resolve Configuration with the provided Issuer of
- invalid_user_info_response
- Unable to resolve the Configuration with the provided…
- An error occurred reading the OAuth 2.0 Authorization…
- An error occurred reading the OAuth 2.0 Device…
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/349fc9371c1c0401.
Report an issue: GitHub.
Appendix: source
Thrown at oauth2/oauth2-client/src/main/java/org/springframework/security/oauth2/client/registration/ClientRegistrations.java:294
try {
return supplier.get();
}
catch (HttpClientErrorException ex) {
if (!ex.getStatusCode().is4xxClientError()) {
throw ex;
}
errors.add(ex.getMessage());
// else try another endpoint
}
catch (IllegalArgumentException | IllegalStateException ex) {
throw ex;
}
catch (RuntimeException ex) {
throw new IllegalArgumentException(errorMessage, ex);
}
}
if (!errors.isEmpty()) {
throw new IllegalArgumentException(errorMessage + ", errors: " + errors);
}
throw new IllegalArgumentException(errorMessage);
}
private static <T> T parseInput(Map<String, Object> body, ThrowingFunction<JSONObject, T, ParseException> parser) {
try {
return parse(body, parser);
}
catch (RuntimeException ex) {
throw new IllegalArgumentException(ex);
}
}
private static <T> T parse(Map<String, Object> body, ThrowingFunction<JSONObject, T, ParseException> parser) {
try {
return parser.apply(new JSONObject(body));
}
catch (ParseException ex) {View on GitHub (pinned to 96852e8860)