invalid_client 🔐 Authentication

OAuth 2.0 Error: invalid_client

The OAuth server couldn’t authenticate your application — wrong client ID/secret, wrong auth method, or the client doesn’t exist in that tenant/environment.

Seen on: Linux Azure REST API

Meaning

invalid_client is about the *app*, not the user. The token endpoint rejected the client credentials. Usually returned with HTTP 401 and sometimes a WWW-Authenticate header naming the expected method (client_secret_basic vs client_secret_post).

Common causes

  • Client secret wrong, expired or rotated (Azure secrets expire)
  • Client ID from a different environment/tenant
  • Sending credentials in the body when the server expects HTTP Basic (or vice versa)
  • Secret not URL-encoded inside the Basic auth header
  • Public client (SPA/mobile) sending a secret, or confidential client missing one

⚡ Quick fix

  1. Copy a fresh secret value (not the secret ID) from the provider console
  2. Match the token endpoint auth method configured for the client
  3. Check client ID and tenant/issuer URL belong together

Detailed fix by platform

Linux

  1. Client credentials with HTTP Basic (client_secret_basic):
    bash
    curl -s -u "$CLIENT_ID:$CLIENT_SECRET" \
      -d grant_type=client_credentials -d scope="api.read" \
      https://auth.example.com/oauth2/token

Azure

  1. AADSTS7000215 = invalid client secret (often the secret *ID* was used instead of its value); AADSTS7000222 = secret expired.

How to diagnose

  1. Credentials — Right client ID + current secret value?
  2. Method — Basic header or form body — which does the client expect?
  3. Tenant — Token endpoint/issuer matches where the app is registered?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.