OAuth 2.0 Error: unsupported_grant_type
The token endpoint didn’t recognise grant_type — usually because the body wasn’t sent as application/x-www-form-urlencoded, or the value is misspelled.
Seen on:
REST API
Meaning
Token requests must be form-encoded. Sending JSON (fetch with JSON.stringify), putting parameters in the query string, or typos (authorisation_code) make the server think grant_type is missing.
Common causes
- Body sent as JSON instead of form-urlencoded
- grant_type in the URL query instead of the body
- Typo in the grant type value
- Provider doesn’t support that grant (password grant disabled)
⚡ Quick fix
- Send Content-Type: application/x-www-form-urlencoded with URLSearchParams
- Check the exact grant_type string
- Use a supported grant
Detailed fix by platform
JavaScript
- javascript
await fetch(tokenUrl, { method: "POST", headers: { "Content-Type": "application/x-www-form-urlencoded" }, body: new URLSearchParams({ grant_type: "authorization_code", code, redirect_uri, client_id, code_verifier }) });
How to diagnose
- Body — Encoding and fields
- Value — grant_type spelling
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- auth/popup-closed-by-user Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
- auth/unauthorized-domain Firebase Auth: auth/unauthorized-domain — This domain is not authorized for OAuth operations for your Firebase project
- bad_verification_code GitHub OAuth: {"error":"bad_verification_code","error_description":"The code passed is incorrect or expired."}
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026