OAuth 2.0 Error: invalid_client
The OAuth server couldn’t authenticate your application — wrong client ID/secret, wrong auth method, or the client doesn’t exist in that tenant/environment.
Meaning
invalid_client is about the *app*, not the user. The token endpoint rejected the client credentials. Usually returned with HTTP 401 and sometimes a WWW-Authenticate header naming the expected method (client_secret_basic vs client_secret_post).
Common causes
- Client secret wrong, expired or rotated (Azure secrets expire)
- Client ID from a different environment/tenant
- Sending credentials in the body when the server expects HTTP Basic (or vice versa)
- Secret not URL-encoded inside the Basic auth header
- Public client (SPA/mobile) sending a secret, or confidential client missing one
⚡ Quick fix
- Copy a fresh secret value (not the secret ID) from the provider console
- Match the token endpoint auth method configured for the client
- Check client ID and tenant/issuer URL belong together
Detailed fix by platform
Linux
- Client credentials with HTTP Basic (client_secret_basic):bash
curl -s -u "$CLIENT_ID:$CLIENT_SECRET" \ -d grant_type=client_credentials -d scope="api.read" \ https://auth.example.com/oauth2/token
Azure
- AADSTS7000215 = invalid client secret (often the secret *ID* was used instead of its value); AADSTS7000222 = secret expired.
How to diagnose
- Credentials — Right client ID + current secret value?
- Method — Basic header or form body — which does the client expect?
- Tenant — Token endpoint/issuer matches where the app is registered?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026