Invalid Grant using Refresh Token

Florian Ritterhoff florian.ritterhoff at hm.edu
Mon Aug 24 12:18:15 UTC 2026


Ok … it is really an expiry bug - so it comes from the app itself. Then we have to dig into the app. Thanks anyway!

Flo 

> On 24. Aug 2026, at 14:00, Henri Mikkonen <henri.mikkonen at nimbleidm.com> wrote:
> 
> [Some people who received this message don't often get email from henri.mikkonen at nimbleidm.com. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
> 
> Hi,
> 
> The logger for net.shibboleth.shared.security.DataSealer seems to
> produce following line on DEBUG:
> 
> DEBUG [net.shibboleth.shared.security.DataSealer:329] - Unwrapped data
> has expired
> 
> Note that DEBUG level may produce privacy-sensitive data to the logs.
> 
> FYI: I also filed OP-specific ticket for this:
> https://shibboleth.atlassian.net/browse/JOIDC-286
> 
> BR,
> Henri.
> 
> On 24.8.2026 14.36, Florian Ritterhoff via users wrote:
>> Hi Henri,
>> 
>> Out of curiosity, is there maybe some logging option we could set to debug to dig a bit into our current issue?
>> 
>> Thanks
>> Flo
>> 
>>> On 24. Aug 2026, at 13:31, Henri Mikkonen <henri.mikkonen at nimbleidm.com> wrote:
>>> 
>>> [Some people who received this message don't often get email from henri.mikkonen at nimbleidm.com. Learn why this is important at https://aka.ms/LearnAboutSenderIdentification ]
>>> 
>>> Hi,
>>> 
>>> In addition to the corrupted token contents (which means that it cannot
>>> be unsealed as you said), also the use of expired refresh token causes
>>> similar log line.
>>> 
>>> It'll be improved for the future release once the OP code exploits the
>>> latest underlying APIs:
>>> 
>>> https://shibboleth.atlassian.net/browse/JSSH-80
>>> 
>>> BR,
>>> Henri.
>>> 
>>> 
>>> On 24.8.2026 13.54, Florian Ritterhoff via users wrote:
>>>> Hi together,
>>>> 
>>>> We are using OIDC + Refresh Tokens for some Apps. We irregularly see some strange InvalidGrant responses from the IDP without a real explanation. Is there any chance that we can debug that on our own and try to understand what’s going on here? From my understanding the only way to trigger the following message would be that the refresh token unsealing broke ...
>>>> 
>>>> WARN [net.shibboleth.idp.plugin.oidc.op.profile.impl.ValidateGrant:349] - Profile Action ValidateGrant: Unwrapping refresh token failed
>>>> 
>>>> Thanks
>>>> Flo
>>>> 
>>>> 
>>> 
>>> --
>>> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
>>> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net
>> 
>> 
> 
> --
> For Consortium Member technical support, see https://shibboleth.atlassian.net/wiki/x/ZYEpPw
> To unsubscribe from this list send an email to users-unsubscribe at shibboleth.net

-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 4507 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20260824/137faabc/attachment.p7s>


More information about the users mailing list