GitHub OAuth: {"error":"bad_verification_code","error_description":"The code passed is incorrect or expired."}
The authorization code sent to GitHub’s token endpoint was already used, expired (10 minutes), or belongs to another OAuth app.
Seen on:
REST API
Meaning
Codes are single-use. Double requests (React StrictMode, retries, page refresh on callback) consume the code, and the second exchange fails. Mixing client IDs between environments also fails.
Common causes
- Code exchanged twice (StrictMode double effect, retries, refresh)
- Code older than 10 minutes
- client_id/secret from another OAuth app
- redirect_uri differs from the authorize request
⚡ Quick fix
- Exchange the code once on the server and redirect away from the callback URL
- Guard against duplicate exchange
- Use matching client credentials per environment
Detailed fix by platform
JavaScript
- javascript
// Next.js route handler — exchange once, then redirect const r = await fetch("https://github.com/login/oauth/access_token", { method: "POST", headers: { Accept: "application/json" }, body: new URLSearchParams({ client_id, client_secret, code }) });
How to diagnose
- Requests — How many exchanges per code?
- Age — Time since redirect
- App — Client ID matches?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS500113 AADSTS500113: No reply address is registered for the application
- Access blocked: has not completed the Google verification process Google OAuth: Error 403: access_denied — The developer hasn't given you access to this app / has not completed the Google verification process
- access_denied OAuth 2.0 Error: access_denied (The user or authorization server denied the request)
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026