Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

In a Spring Boot servlet application, Spring Security gets the authorization code through the OAuth 2.0 authorization-code flow: send the user to /oauth2/authorization/{registrationId}, let the provider authenticate and authorize them, then receive the code at the configured callback. Spring Security exchanges that code with the provider’s token endpoint; the code is an intermediate value, not an access token.

How do I get the authorization code in Spring Boot?

  1. Add Spring Boot’s OAuth2 client starter, spring-boot-starter-oauth2-client. It provides OAuth2 client features for login and obtaining tokens to access a third-party API. See Spring Boot’s security reference.

  2. Configure a client registration with the provider’s client ID, authorization grant type, callback URI, and scopes. Add a client secret only when the application is a confidential client and the provider requires it.

  3. Start the flow by directing the browser to /oauth2/authorization/{registrationId}, replacing {registrationId} with the registration’s ID. Spring Security resolves the registration, builds an authorization request, and redirects the browser to the provider’s authorization endpoint. The default behavior is documented in the Spring Security authorization-grants reference.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  4. After the user authenticates and approves access, the provider redirects the browser to the registered callback URI with a code parameter. Spring Security handles the callback and uses the code in a request to the token endpoint.

OAuth 2.0 Login uses the Authorization Code Grant. In practical terms, your application normally does not receive an access token in the browser redirect: it receives the code, then Spring Security performs the token exchange.

How do I configure OAuth2 login in Spring Boot?

A registration tells Spring which client is making the request; provider settings tell it where to send authorization and token requests. For example:

spring:
  security:
    oauth2:
      client:
        registration:
          provider-name:
            client-id: client-id
            client-secret: client-secret
            authorization-grant-type: authorization_code
            redirect-uri: "{baseUrl}/login/oauth2/code/{registrationId}"
            scope: openid, profile
        provider:
          provider-name:
            authorization-uri: https://provider.example/authorize
            token-uri: https://provider.example/token

This is a shape to adapt, not a set of universal provider values. Replace the illustrative registration ID, credentials, endpoints, scopes, and callback with values supported by your identity or authorization provider. Spring Boot’s OAuth2 client configuration reference describes the registration properties.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose explicit endpoints or issuer discovery

You can configure provider endpoints such as authorization-uri and token-uri directly. Where supported, an issuer-uri can let Spring discover provider metadata instead. Use the provider’s documented issuer and endpoint details rather than copying example URLs; the available properties are described in Spring Security’s client core reference.

Decide whether this is OAuth2 API access or OIDC login

OAuth2 is an authorization framework; by itself it is not an identity protocol. Spring Security activates OpenID Connect processing when the requested scopes include openid. Without that scope, it uses OAuth2 user processing. Choose scopes that match the provider and your use case. See the Spring Security OAuth2 Login reference.

What is the redirect URI for Spring Security OAuth2 login?

The redirect URI is the callback address to which the provider sends the browser after authentication and consent. The example uses {baseUrl}/login/oauth2/code/{registrationId}; the actual expanded URI depends on your application’s configuration and deployment. Register the exact externally visible URI with the provider, and make sure it matches the URI Spring uses. Configuring a URI in Spring does not register it with the provider.

When the application is behind a reverse proxy

Spring must construct a callback with the public scheme, host, port, and path—not an internal address that the provider cannot reach. For a proxied deployment, verify forwarded-header processing and that the proxy supplies the required forwarded headers. Spring Security documents redirect URI templates and proxy-related handling in its authorization-grants reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Should the OAuth2 client be confidential or public?

A confidential client can protect its credentials in a trusted server-side environment. A public client cannot reliably keep a secret private, so do not embed a client secret in an untrusted browser or native application. Spring Security supports PKCE for public clients. Its reference describes automatic PKCE use when the client secret is absent and the authentication method is none, or when requireProofKey is enabled for an authorization-code registration. Confirm that the provider supports the PKCE configuration you choose; details are in the Spring Security authorization-grants reference.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What to check if the callback does not work

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.