In a Spring Boot servlet application, Spring Security gets the authorization code through the OAuth 2.0 authorization-code flow: send the user to /oauth2/authorization/{registrationId}, let the provider authenticate and authorize them, then receive the code at the configured callback. Spring Security exchanges that code with the provider’s token endpoint; the code is an intermediate value, not an access token.
How do I get the authorization code in Spring Boot?
-
Add Spring Boot’s OAuth2 client starter,
spring-boot-starter-oauth2-client. It provides OAuth2 client features for login and obtaining tokens to access a third-party API. See Spring Boot’s security reference. -
Configure a client registration with the provider’s client ID, authorization grant type, callback URI, and scopes. Add a client secret only when the application is a confidential client and the provider requires it.
-
Start the flow by directing the browser to
/oauth2/authorization/{registrationId}, replacing{registrationId}with the registration’s ID. Spring Security resolves the registration, builds an authorization request, and redirects the browser to the provider’s authorization endpoint. The default behavior is documented in the Spring Security authorization-grants reference.Recommended: Fix Windows Errors and Clear Junk Files in Minutes - Free Scan →Recommended: Update Every Outdated Driver on Your PC in One Scan - Free →Recommended: PC Feels Slow? A Free Scan Shows What's Dragging Windows Down →Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy. -
After the user authenticates and approves access, the provider redirects the browser to the registered callback URI with a
codeparameter. Spring Security handles the callback and uses the code in a request to the token endpoint.
OAuth 2.0 Login uses the Authorization Code Grant. In practical terms, your application normally does not receive an access token in the browser redirect: it receives the code, then Spring Security performs the token exchange.
How do I configure OAuth2 login in Spring Boot?
A registration tells Spring which client is making the request; provider settings tell it where to send authorization and token requests. For example:
spring:
security:
oauth2:
client:
registration:
provider-name:
client-id: client-id
client-secret: client-secret
authorization-grant-type: authorization_code
redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
scope: openid, profile
provider:
provider-name:
authorization-uri: https://provider.example/authorize
token-uri: https://provider.example/token
This is a shape to adapt, not a set of universal provider values. Replace the illustrative registration ID, credentials, endpoints, scopes, and callback with values supported by your identity or authorization provider. Spring Boot’s OAuth2 client configuration reference describes the registration properties.
Free tools Windows power users keep installed
One-click scans. No signup required.
Choose explicit endpoints or issuer discovery
You can configure provider endpoints such as authorization-uri and token-uri directly. Where supported, an issuer-uri can let Spring discover provider metadata instead. Use the provider’s documented issuer and endpoint details rather than copying example URLs; the available properties are described in Spring Security’s client core reference.
Decide whether this is OAuth2 API access or OIDC login
OAuth2 is an authorization framework; by itself it is not an identity protocol. Spring Security activates OpenID Connect processing when the requested scopes include openid. Without that scope, it uses OAuth2 user processing. Choose scopes that match the provider and your use case. See the Spring Security OAuth2 Login reference.
Rank #3
What is the redirect URI for Spring Security OAuth2 login?
The redirect URI is the callback address to which the provider sends the browser after authentication and consent. The example uses {baseUrl}/login/oauth2/code/{registrationId}; the actual expanded URI depends on your application’s configuration and deployment. Register the exact externally visible URI with the provider, and make sure it matches the URI Spring uses. Configuring a URI in Spring does not register it with the provider.
When the application is behind a reverse proxy
Spring must construct a callback with the public scheme, host, port, and path—not an internal address that the provider cannot reach. For a proxied deployment, verify forwarded-header processing and that the proxy supplies the required forwarded headers. Spring Security documents redirect URI templates and proxy-related handling in its authorization-grants reference.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →Should the OAuth2 client be confidential or public?
A confidential client can protect its credentials in a trusted server-side environment. A public client cannot reliably keep a secret private, so do not embed a client secret in an untrusted browser or native application. Spring Security supports PKCE for public clients. Its reference describes automatic PKCE use when the client secret is absent and the authentication method is none, or when requireProofKey is enabled for an authorization-code registration. Confirm that the provider supports the PKCE configuration you choose; details are in the Spring Security authorization-grants reference.
Rank #4
- Used Book in Good Condition
What to check if the callback does not work
-
Registration ID: The path segment in
/oauth2/authorization/{registrationId}must identify a configured registration. -
Callback match: Compare the fully expanded redirect URI from the application with the URI registered at the provider, including scheme, hostname, port, and path.
-
Provider settings: Confirm the authorization and token endpoints—or the issuer used for metadata discovery—belong to the selected provider.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.Best Value
-
Client type and PKCE: Do not send a secret from a public client; configure PKCE as required by your provider and Spring Security setup.
-
Framework version: Match configuration and behavior to the Spring Boot and Spring Security versions used by your project. Spring’s current reference identified here is Spring Security 7.1.1; do not assume every version has identical APIs or defaults. See the Spring Security reference.
Quick Recap
Bestseller No. 1Bestseller No. 2Bestseller No. 3SaleBestseller No. 4Bestseller No. 5
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

