unauthorized_client 🔐 Authentication

OAuth 2.0 Error: unauthorized_client (client not allowed to use this grant type)

The client exists, but isn’t allowed to use the requested flow (grant type or response type).

Seen on: REST API

Meaning

Identity providers enable grant types per application: authorization_code, client_credentials, refresh_token, device_code, implicit. Auth0 says “Grant type 'X' not allowed for the client”, Okta “The client is not authorized to use the provided grant type”.

Common causes

  • Grant type not enabled for the app (client_credentials, password, refresh_token)
  • App type mismatch (SPA vs regular web vs native)
  • Implicit flow disabled

⚡ Quick fix

  1. Enable the grant type in the provider’s app settings
  2. Use the flow matching the app type (auth code + PKCE for SPAs/mobile)
  3. Create a machine-to-machine app for client_credentials

Detailed fix by platform

Shell

  1. curl -s -X POST https://auth.example.com/oauth/token -d grant_type=client_credentials -d client_id=$ID -d client_secret=$SECRET -d audience=https://api.example.com

How to diagnose

  1. Grant — Which grant type is sent?
  2. App settings — Allowed grants
  3. App type — SPA/native/M2M

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.