OIDC Error: nonce mismatch / ID token nonce did not match / unexpected nonce
The nonce inside the ID token doesn’t match the one the app stored — the replay protection check failed.
Seen on:
REST API
Meaning
Like state, the nonce must be stored before redirect and compared after. Lost cookies/storage, multiple login attempts in parallel, or caching the callback cause mismatches.
Common causes
- Nonce cookie/storage lost before callback
- Concurrent login attempts overwriting the stored nonce
- Reusing an old ID token
- Proxy caching the login page
⚡ Quick fix
- Store nonce alongside state for the same request
- Avoid multiple simultaneous login flows
- Don’t cache auth endpoints
Detailed fix by platform
JavaScript
- javascript
// openid-client const tokens = await client.callback(redirectUri, params, { state: req.session.state, nonce: req.session.nonce, code_verifier: req.session.verifier });
How to diagnose
- Storage — Nonce available?
- Flows — Parallel logins?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- antiforgery token could not be decrypted ASP.NET Core: The antiforgery token could not be decrypted / The required antiforgery cookie is not present (400 Bad Request)
- invalid algorithm JWT error: invalid algorithm / The specified alg value is not allowed / jwt signature is required
- invalid csrf token ForbiddenError: invalid csrf token (EBADCSRFTOKEN)
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026