nonce mismatch 🔐 Authentication

OIDC Error: nonce mismatch / ID token nonce did not match / unexpected nonce

The nonce inside the ID token doesn’t match the one the app stored — the replay protection check failed.

Seen on: REST API

Meaning

Like state, the nonce must be stored before redirect and compared after. Lost cookies/storage, multiple login attempts in parallel, or caching the callback cause mismatches.

Common causes

  • Nonce cookie/storage lost before callback
  • Concurrent login attempts overwriting the stored nonce
  • Reusing an old ID token
  • Proxy caching the login page

⚡ Quick fix

  1. Store nonce alongside state for the same request
  2. Avoid multiple simultaneous login flows
  3. Don’t cache auth endpoints

Detailed fix by platform

JavaScript

  1. javascript
    // openid-client
    const tokens = await client.callback(redirectUri, params, { state: req.session.state, nonce: req.session.nonce, code_verifier: req.session.verifier });

How to diagnose

  1. Storage — Nonce available?
  2. Flows — Parallel logins?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.