Invalid parameter: redirect_uri 🔐 Authentication

Keycloak: We are sorry... Invalid parameter: redirect_uri

The redirect_uri in the login request isn’t in the Keycloak client’s Valid Redirect URIs.

Seen on: REST API

Meaning

Keycloak matches exactly or by wildcard. Ports, trailing slashes, http vs https behind proxies, and different hostnames (localhost vs 127.0.0.1) cause mismatches. Behind a proxy, Keycloak may also see the wrong scheme.

Common causes

  • URI not listed in Valid Redirect URIs
  • http vs https (proxy without forwarded headers)
  • Port/hostname/trailing slash differences
  • Using the wrong client

⚡ Quick fix

  1. Add the exact URI (or a careful wildcard) to Valid Redirect URIs
  2. Configure proxy headers (KC_PROXY_HEADERS=xforwarded)
  3. Use the same hostname consistently

Detailed fix by platform

Shell

  1. bash
    # Keycloak 24+ behind a reverse proxy
    KC_PROXY_HEADERS=xforwarded KC_HOSTNAME=https://auth.example.com /opt/keycloak/bin/kc.sh start

How to diagnose

  1. Request — redirect_uri parameter value
  2. Client — Valid Redirect URIs
  3. Proxy — Forwarded headers

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.