Keycloak: invalid_grant — Account is not fully set up
The user has pending required actions (verify email, update password, configure OTP), so non-interactive token requests (password grant) fail.
Seen on:
REST API
Meaning
Required actions can only be completed in the browser login flow. Clear them for service/test users or log in interactively once.
Common causes
- Required actions on the user (Verify Email, Update Password, Configure OTP)
- Password grant used for a user with pending actions
- Temporary password set by an admin
⚡ Quick fix
- Remove required actions in the admin console (Users → Details)
- Set non-temporary passwords for test/service users
- Use the browser flow to complete actions
Detailed fix by platform
Shell
- bash
# kcadm /opt/keycloak/bin/kcadm.sh update users/$USER_ID -r myrealm -s 'requiredActions=[]'
How to diagnose
- User — Required actions list
- Password — Temporary?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026