IDX20803 🟪 .NET

IDX20803: Unable to obtain configuration from: 'https://login.example.com/.well-known/openid-configuration'

The OpenID Connect / JWT bearer middleware couldn’t download the identity provider’s metadata, so it can’t validate tokens or redirect to login.

Seen on: .NET

Meaning

The app fetches /.well-known/openid-configuration at startup or first request. Wrong Authority URL, no outbound internet/proxy, TLS trust problems in containers, or the IdP being down cause IDX20803 (often wrapping IDX20804).

Common causes

  • Authority URL wrong (missing tenant, trailing path)
  • No outbound access / proxy not configured
  • Container doesn’t trust the IdP’s certificate chain
  • IdP outage or local IdP not running

⚡ Quick fix

  1. Open the metadata URL from the server (curl)
  2. Fix Authority (e.g. https://login.microsoftonline.com/{tenant}/v2.0)
  3. Configure proxy/CA certificates for the container

Detailed fix by platform

Shell

  1. curl -sS https://login.example.com/.well-known/openid-configuration | head -c 300

How to diagnose

  1. URL — Reachable from the app host?
  2. Inner — IDX20804 / SSL / DNS message
  3. Proxy — Needed?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.