IDX20803: Unable to obtain configuration from: 'https://login.example.com/.well-known/openid-configuration'
The OpenID Connect / JWT bearer middleware couldn’t download the identity provider’s metadata, so it can’t validate tokens or redirect to login.
Seen on:
.NET
Meaning
The app fetches /.well-known/openid-configuration at startup or first request. Wrong Authority URL, no outbound internet/proxy, TLS trust problems in containers, or the IdP being down cause IDX20803 (often wrapping IDX20804).
Common causes
- Authority URL wrong (missing tenant, trailing path)
- No outbound access / proxy not configured
- Container doesn’t trust the IdP’s certificate chain
- IdP outage or local IdP not running
⚡ Quick fix
- Open the metadata URL from the server (curl)
- Fix Authority (e.g. https://login.microsoftonline.com/{tenant}/v2.0)
- Configure proxy/CA certificates for the container
Detailed fix by platform
Shell
curl -sS https://login.example.com/.well-known/openid-configuration | head -c 300
How to diagnose
- URL — Reachable from the app host?
- Inner — IDX20804 / SSL / DNS message
- Proxy — Needed?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in .NET
- NullReferenceException System.NullReferenceException: Object reference not set to an instance of an object
- FileNotFoundException assembly Could not load file or assembly 'X, Version=…' or one of its dependencies
- InvalidOperationException InvalidOperationException: Unable to resolve service for type 'X' while attempting to activate 'Y'
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026