OAuth callback error: state mismatch / Unable to verify authorization request state / State cookie was missing
The state value returned to the callback doesn’t match what the app stored before redirecting — the CSRF protection for OAuth failed.
Seen on:
REST API
Meaning
The app stores state (cookie/session) before sending the user to the IdP. If that cookie is lost (SameSite, different domain/port, session store not shared between instances), or the user finishes login in another tab, the check fails.
Common causes
- State cookie blocked or not sent back (SameSite, secure flag on http)
- Callback on a different domain/subdomain than where login started
- Session store not shared across instances
- Back button / double-submit / multiple tabs
⚡ Quick fix
- Start and finish login on the same host (same scheme and port)
- Use SameSite=Lax cookies and HTTPS
- Use a shared session store (Redis) behind load balancers
Detailed fix by platform
JavaScript
- javascript
// express-session behind a proxy app.set("trust proxy", 1); app.use(session({ store: new RedisStore({ client }), cookie: { secure: true, sameSite: "lax" }, resave: false, saveUninitialized: false, secret }));
How to diagnose
- Cookie — Present at callback?
- Hosts — Same origin?
- Instances — Shared sessions?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026