Keycloak: We are sorry... Invalid parameter: redirect_uri
The redirect_uri in the login request isn’t in the Keycloak client’s Valid Redirect URIs.
Seen on:
REST API
Meaning
Keycloak matches exactly or by wildcard. Ports, trailing slashes, http vs https behind proxies, and different hostnames (localhost vs 127.0.0.1) cause mismatches. Behind a proxy, Keycloak may also see the wrong scheme.
Common causes
- URI not listed in Valid Redirect URIs
- http vs https (proxy without forwarded headers)
- Port/hostname/trailing slash differences
- Using the wrong client
⚡ Quick fix
- Add the exact URI (or a careful wildcard) to Valid Redirect URIs
- Configure proxy headers (KC_PROXY_HEADERS=xforwarded)
- Use the same hostname consistently
Detailed fix by platform
Shell
- bash
# Keycloak 24+ behind a reverse proxy KC_PROXY_HEADERS=xforwarded KC_HOSTNAME=https://auth.example.com /opt/keycloak/bin/kc.sh start
How to diagnose
- Request — redirect_uri parameter value
- Client — Valid Redirect URIs
- Proxy — Forwarded headers
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- Account is not fully set up Keycloak: invalid_grant — Account is not fully set up
- auth/popup-closed-by-user Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
- auth/unauthorized-domain Firebase Auth: auth/unauthorized-domain — This domain is not authorized for OAuth operations for your Firebase project
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026