OAuth 2.0 Error: unauthorized_client (client not allowed to use this grant type)
The client exists, but isn’t allowed to use the requested flow (grant type or response type).
Seen on:
REST API
Meaning
Identity providers enable grant types per application: authorization_code, client_credentials, refresh_token, device_code, implicit. Auth0 says “Grant type 'X' not allowed for the client”, Okta “The client is not authorized to use the provided grant type”.
Common causes
- Grant type not enabled for the app (client_credentials, password, refresh_token)
- App type mismatch (SPA vs regular web vs native)
- Implicit flow disabled
⚡ Quick fix
- Enable the grant type in the provider’s app settings
- Use the flow matching the app type (auth code + PKCE for SPAs/mobile)
- Create a machine-to-machine app for client_credentials
Detailed fix by platform
Shell
curl -s -X POST https://auth.example.com/oauth/token -d grant_type=client_credentials -d client_id=$ID -d client_secret=$SECRET -d audience=https://api.example.com
How to diagnose
- Grant — Which grant type is sent?
- App settings — Allowed grants
- App type — SPA/native/M2M
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AH00558 Apache: AH00558: apache2: Could not reliably determine the server's fully qualified domain name
- auth/popup-closed-by-user Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
- auth/unauthorized-domain Firebase Auth: auth/unauthorized-domain — This domain is not authorized for OAuth operations for your Firebase project
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026