invalid_request 🔐 Authentication

OAuth 2.0 Error: invalid_request (missing or invalid parameter)

The authorization or token request is malformed — a required parameter is missing, duplicated, or has an invalid value.

Seen on: REST API

Meaning

The error_description usually names the parameter: missing redirect_uri, client_id, code_verifier, invalid scope format, or duplicated parameters from bad URL building. Google shows “Error 400: invalid_request”.

Common causes

  • Required parameter missing (redirect_uri, client_id, code_challenge)
  • Parameter sent twice or badly encoded
  • PKCE required but not sent
  • Request violating provider policy (Google: insecure WebView/OOB flow)

⚡ Quick fix

  1. Read error_description for the parameter
  2. Log the full authorize/token request
  3. Compare with the provider’s documented parameters

Detailed fix by platform

Shell

  1. bash
    # decode the authorize URL you send
    python3 -c "import sys,urllib.parse as u;print(u.parse_qs(u.urlparse(sys.argv[1]).query))" "$AUTH_URL"

How to diagnose

  1. Description — Named parameter
  2. Request — Full parameter list
  3. Policy — Provider requirements (PKCE, HTTPS)

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.