Invalid Grant using Refresh Token
Henri Mikkonen
henri.mikkonen at nimbleidm.com
Mon Aug 24 11:31:33 UTC 2026
Hi,
In addition to the corrupted token contents (which means that it cannot
be unsealed as you said), also the use of expired refresh token causes
similar log line.
It'll be improved for the future release once the OP code exploits the
latest underlying APIs:
https://shibboleth.atlassian.net/browse/JSSH-80
BR,
Henri.
On 24.8.2026 13.54, Florian Ritterhoff via users wrote:
> Hi together,
>
> We are using OIDC + Refresh Tokens for some Apps. We irregularly see some strange InvalidGrant responses from the IDP without a real explanation. Is there any chance that we can debug that on our own and try to understand what’s going on here? From my understanding the only way to trigger the following message would be that the refresh token unsealing broke ...
>
> WARN [net.shibboleth.idp.plugin.oidc.op.profile.impl.ValidateGrant:349] - Profile Action ValidateGrant: Unwrapping refresh token failed
>
> Thanks
> Flo
>
>
More information about the users
mailing list