redirect_uri_mismatch 🔐 Authentication

OAuth Error: redirect_uri_mismatch

The redirect URI in your OAuth request doesn’t exactly match one registered for the client in the provider’s console.

Seen on: Google Microsoft

Meaning

OAuth providers only redirect back to pre-registered URLs to prevent token theft. The comparison is exact: scheme, host, port, path and trailing slash must all match.

Common causes

  • http vs https or www vs non-www mismatch
  • Trailing slash difference (/callback vs /callback/)
  • Different port in development (localhost:3000 vs localhost:5173)
  • App behind a proxy builds the URL with the internal host/scheme
  • Using the wrong client ID (dev vs prod)

⚡ Quick fix

  1. Copy the redirect_uri from the error/authorize URL and register it exactly
  2. Hard-code the redirect URI in config rather than deriving it from the request
  3. Behind a proxy, trust X-Forwarded-Proto/Host so generated URLs use https

Detailed fix by platform

Google

  1. Google Cloud Console → APIs & Services → Credentials → OAuth client → Authorized redirect URIs. Changes can take a few minutes.

Microsoft

  1. Entra ID → App registrations → Authentication → add the URI under the right platform (Web vs SPA). Error code AADSTS50011.

How to diagnose

  1. Sent URI — What redirect_uri is in the authorize URL?
  2. Registered URIs — Exact match including slash and port?
  3. Client ID — Right environment?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.