OAuth Error: redirect_uri_mismatch
The redirect URI in your OAuth request doesn’t exactly match one registered for the client in the provider’s console.
Meaning
OAuth providers only redirect back to pre-registered URLs to prevent token theft. The comparison is exact: scheme, host, port, path and trailing slash must all match.
Common causes
- http vs https or www vs non-www mismatch
- Trailing slash difference (
/callbackvs/callback/) - Different port in development (localhost:3000 vs localhost:5173)
- App behind a proxy builds the URL with the internal host/scheme
- Using the wrong client ID (dev vs prod)
⚡ Quick fix
- Copy the redirect_uri from the error/authorize URL and register it exactly
- Hard-code the redirect URI in config rather than deriving it from the request
- Behind a proxy, trust
X-Forwarded-Proto/Hostso generated URLs use https
Detailed fix by platform
- Google Cloud Console → APIs & Services → Credentials → OAuth client → Authorized redirect URIs. Changes can take a few minutes.
Microsoft
- Entra ID → App registrations → Authentication → add the URI under the right platform (Web vs SPA). Error code AADSTS50011.
How to diagnose
- Sent URI — What redirect_uri is in the authorize URL?
- Registered URIs — Exact match including slash and port?
- Client ID — Right environment?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026