spring-projects/spring-security · error · IllegalArgumentException

Unable to resolve the Configuration with the provided…

Error message

Unable to resolve the Configuration with the provided Issuer of "" + issuer

What it means

Spring Security could not fetch the OIDC/OAuth2 provider configuration (/.well-known/openid-configuration or /.well-known/oauth-authorization-server) for the given issuer. After trying each well-known endpoint, a non-4xx-client-error runtime failure (network error, 5xx, connection refused) occurred, so it wraps it in this IllegalArgumentException with the issuer in the message.

Solutions

  1. Verify the issuer URI is correct and reachable: curl <issuer>/.well-known/openid-configuration from the host running the app.
  2. Fix network/DNS/firewall or proxy settings so the app can reach the authorization server.
  3. If the server starts before the provider, retry later or configure the decoder lazily / with jwk-set-uri instead of issuer-uri to skip discovery at startup.
  4. If the provider returns 5xx on discovery, fix or check the authorization server's discovery endpoint configuration.

Example fix

// before
spring.security.oauth2.resourceserver.jwt.issuer-uri=https://auth.example.com WRONG (typo'd host)
// after
spring.security.oauth2.resourceserver.jwt.issuer-uri=https://auth-server.example.com
Defensive patterns

Strategy: try-catch

Validate before calling

// preflight in shell
// curl -fsS "$ISSUER/.well-known/openid-configuration" > /dev/null && echo reachable

Try / catch

try { JwtDecoder d = JwtDecoders.fromIssuerLocation(issuer); }
catch (IllegalArgumentException e) {
    // configuration/startup failure: check connectivity to issuer, retry or fail fast
}

Prevention

When it happens

Trigger: JwtDecoderProviderConfigurationUtils.getConfiguration called via getConfigurationForIssuerLocation/getConfigurationForOidcIssuerLocation; the GET to the discovery endpoint throws a RuntimeException that is not an HttpClientErrorException with a 4xx status (e.g. connection refused, DNS failure, timeout, 500 response).

Common situations: Typo'd issuer URL in application.yml (issuer property of spring.security.oauth2.resourceserver.jwt.issuer-uri); authorization server unreachable from the app's network; discovery endpoint returning 5xx; TLS certificate issues; the app starting before the auth server is up.

Understand the failure class

Background: 'Something went wrong' / 'Request failed (500)' / 'HTTP error! status: 404' — what failed HTTP requests actually mean and how to find the real cause — this error's family across 28 libraries.

Related errors


AI-assisted analysis of spring-projects/spring-security@96852e8860 (2026-09-10). Data as JSON: /api/errors/1e1d4a23a4d930fa. Report an issue: GitHub.

Appendix: source

Thrown at oauth2/oauth2-jose/src/main/java/org/springframework/security/oauth2/jwt/JwtDecoderProviderConfigurationUtils.java:199

	@SuppressWarnings("removal")
	private static Map<String, Object> getConfiguration(String issuer, RestOperations rest, UriComponents... uris) {
		String errorMessage = "Unable to resolve the Configuration with the provided Issuer of " + "\"" + issuer + "\"";
		for (UriComponents uri : uris) {
			try {
				RequestEntity<Void> request = RequestEntity.get(uri.toUriString()).build();
				ResponseEntity<Map<String, Object>> response = rest.exchange(request, STRING_OBJECT_MAP);
				Map<String, Object> configuration = response.getBody();
				Assert.notNull(configuration, "configuration must not be null");
				Assert.isTrue(configuration.get("jwks_uri") != null, "The public JWK set URI must not be null");
				return configuration;
			}
			catch (IllegalArgumentException ex) {
				throw ex;
			}
			catch (RuntimeException ex) {
				if (!(ex instanceof HttpClientErrorException
						&& ((HttpClientErrorException) ex).getStatusCode().is4xxClientError())) {
					throw new IllegalArgumentException(errorMessage, ex);
				}
				// else try another endpoint
			}
		}
		throw new IllegalArgumentException(errorMessage);
	}

	static UriComponents oidc(String issuer) {
		UriComponents uri = UriComponentsBuilder.fromUriString(issuer).build();
		// @formatter:off
		return UriComponentsBuilder.newInstance().uriComponents(uri)
				.replacePath(uri.getPath() + OIDC_METADATA_PATH)
				.build();
		// @formatter:on
	}

	static UriComponents oidcRfc8414(String issuer) {
		UriComponents uri = UriComponentsBuilder.fromUriString(issuer).build();

View on GitHub (pinned to 96852e8860)