Invalid Grant using Refresh Token

Henri Mikkonen henri.mikkonen at nimbleidm.com
Mon Aug 24 11:31:33 UTC 2026


Hi,

In addition to the corrupted token contents (which means that it cannot 
be unsealed as you said), also the use of expired refresh token causes 
similar log line.

It'll be improved for the future release once the OP code exploits the 
latest underlying APIs:

https://shibboleth.atlassian.net/browse/JSSH-80

BR,
Henri.


On 24.8.2026 13.54, Florian Ritterhoff via users wrote:
> Hi together,
> 
> We are using OIDC + Refresh Tokens for some Apps. We irregularly see some strange InvalidGrant responses from the IDP without a real explanation. Is there any chance that we can debug that on our own and try to understand what’s going on here? From my understanding the only way to trigger the following message would be that the refresh token unsealing broke ...
> 
> WARN [net.shibboleth.idp.plugin.oidc.op.profile.impl.ValidateGrant:349] - Profile Action ValidateGrant: Unwrapping refresh token failed
> 
> Thanks
> Flo
> 
> 



More information about the users mailing list