spring-projects/spring-security · error · IllegalArgumentException
Unable to resolve the Configuration with the provided…
Error message
Unable to resolve the Configuration with the provided Issuer of "" + issuer
What it means
Spring Security could not fetch the OIDC/OAuth2 provider configuration (/.well-known/openid-configuration or /.well-known/oauth-authorization-server) for the given issuer. After trying each well-known endpoint, a non-4xx-client-error runtime failure (network error, 5xx, connection refused) occurred, so it wraps it in this IllegalArgumentException with the issuer in the message.
Solutions
- Verify the issuer URI is correct and reachable: curl <issuer>/.well-known/openid-configuration from the host running the app.
- Fix network/DNS/firewall or proxy settings so the app can reach the authorization server.
- If the server starts before the provider, retry later or configure the decoder lazily / with jwk-set-uri instead of issuer-uri to skip discovery at startup.
- If the provider returns 5xx on discovery, fix or check the authorization server's discovery endpoint configuration.
Example fix
// before spring.security.oauth2.resourceserver.jwt.issuer-uri=https://auth.example.com WRONG (typo'd host) // after spring.security.oauth2.resourceserver.jwt.issuer-uri=https://auth-server.example.com
Defensive patterns
Strategy: try-catch
Validate before calling
// preflight in shell // curl -fsS "$ISSUER/.well-known/openid-configuration" > /dev/null && echo reachable
Try / catch
try { JwtDecoder d = JwtDecoders.fromIssuerLocation(issuer); }
catch (IllegalArgumentException e) {
// configuration/startup failure: check connectivity to issuer, retry or fail fast
} Prevention
- curl the discovery URL from the app host during deployment health checks
- Prefer jwk-set-uri configuration when discovery is not needed, removing network dependency at startup
- Keep issuer URIs in one config source; validate them with a startup connectivity check
When it happens
Trigger: JwtDecoderProviderConfigurationUtils.getConfiguration called via getConfigurationForIssuerLocation/getConfigurationForOidcIssuerLocation; the GET to the discovery endpoint throws a RuntimeException that is not an HttpClientErrorException with a 4xx status (e.g. connection refused, DNS failure, timeout, 500 response).
Common situations: Typo'd issuer URL in application.yml (issuer property of spring.security.oauth2.resourceserver.jwt.issuer-uri); authorization server unreachable from the app's network; discovery endpoint returning 5xx; TLS certificate issues; the app starting before the auth server is up.
Understand the failure class
Background: 'Something went wrong' / 'Request failed (500)' / 'HTTP error! status: 404' — what failed HTTP requests actually mean and how to find the real cause — this error's family across 28 libraries.
Related errors
- Unable to resolve Configuration with the provided Issuer of
- Unable to resolve Configuration with the provided Issuer of
- invalid_user_info_response
- missing_signature_verifier
- missing_signature_verifier
AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10).
Data as JSON: /api/errors/1e1d4a23a4d930fa.
Report an issue: GitHub.
Appendix: source
Thrown at oauth2/oauth2-jose/src/main/java/org/springframework/security/oauth2/jwt/JwtDecoderProviderConfigurationUtils.java:199
@SuppressWarnings("removal")
private static Map<String, Object> getConfiguration(String issuer, RestOperations rest, UriComponents... uris) {
String errorMessage = "Unable to resolve the Configuration with the provided Issuer of " + "\"" + issuer + "\"";
for (UriComponents uri : uris) {
try {
RequestEntity<Void> request = RequestEntity.get(uri.toUriString()).build();
ResponseEntity<Map<String, Object>> response = rest.exchange(request, STRING_OBJECT_MAP);
Map<String, Object> configuration = response.getBody();
Assert.notNull(configuration, "configuration must not be null");
Assert.isTrue(configuration.get("jwks_uri") != null, "The public JWK set URI must not be null");
return configuration;
}
catch (IllegalArgumentException ex) {
throw ex;
}
catch (RuntimeException ex) {
if (!(ex instanceof HttpClientErrorException
&& ((HttpClientErrorException) ex).getStatusCode().is4xxClientError())) {
throw new IllegalArgumentException(errorMessage, ex);
}
// else try another endpoint
}
}
throw new IllegalArgumentException(errorMessage);
}
static UriComponents oidc(String issuer) {
UriComponents uri = UriComponentsBuilder.fromUriString(issuer).build();
// @formatter:off
return UriComponentsBuilder.newInstance().uriComponents(uri)
.replacePath(uri.getPath() + OIDC_METADATA_PATH)
.build();
// @formatter:on
}
static UriComponents oidcRfc8414(String issuer) {
UriComponents uri = UriComponentsBuilder.fromUriString(issuer).build();View on GitHub (pinned to 96852e8860)