# AADSTS50011: The reply URL specified in the request does not match the reply URLs configured for the application

## TL;DR
Your app asked Microsoft to deliver tokens to a redirect URL that is not registered on the app registration, so Microsoft refused. The comparison is exact: scheme, host, port, path, and trailing slash must all match. Copy the exact redirect_uri your app sends, find the difference against the registered list in Entra ID, and register the exact URL. Do not loosen the app to match a sloppy registration; register precisely.

```text
AADSTS50011: The reply URL specified in the request does not match the reply URLs configured for the application
```

## Use this when
- Microsoft login fails immediately after the user enters credentials
- You just created or edited an app registration
- It works in dev and breaks in prod, or vice versa
- A framework upgrade changed the callback path your app sends

## Not for this skill when
- The error is AADSTS65001 about consent (different problem)
- The client secret expired (that fails at the token endpoint, not the redirect)
- A conditional access policy blocks the user (that names the policy)

## Steps
1. Capture the exact redirect_uri your app sends. Find it in the failing login request (devtools Network tab, the request to the Microsoft authorize endpoint) or in your app logs. Copy the full value.
   Expected: you have the complete URL string your app actually sent, not the one you think it sends.

2. Open the registration and compare character by character. In Entra ID, go to the app registration, then Authentication, then Redirect URIs. Compare against your captured value. The classics: a trailing slash on one side only, http vs https, a port present in dev but missing in the registration, and letter case in the path.
   Expected: you can point to the exact differing character.

3. Register the exact URL under the right platform type. Add the captured URL to the registration. Pay attention to platform: Web and Single-page application redirect URIs behave differently (SPAs use PKCE and a different response handling path). Registering a SPA callback as Web, or the reverse, keeps failing.
   Expected: the exact URL appears in the list under the correct platform.

4. Re-test the login end to end. Clear any cached state and go through the full flow.
   Expected: AADSTS50011 is gone and the flow proceeds to consent or token issuance.

### Variant: works on the machine's dev URL, fails in production
Dev URLs (loopback address with a port) and production URLs are separate registrations entries. Both must be listed. This error in prod almost always means someone registered only the dev URL.

### Variant: trailing slash mismatch
The single most common cause. Your app sends https://example.com/auth/callback and the registration has https://example.com/auth/callback/ (or the reverse). Exact means exact.

### Variant: SPA registered as Web
Single-page apps must use the Single-page application platform type. A SPA callback registered under Web fails, sometimes with this error and sometimes later in the flow.

### Variant: multi-tenant apps
Each tenant's users hit the same registration, but if you run separate registrations per environment, the URL must exist in the registration that matches the client ID your app sends. Check you are editing the right registration.

## Why this happens
The reply URL is where Microsoft delivers authorization codes and tokens. If it accepted unregistered URLs, an attacker could register nothing and still get tokens sent to their own server by tampering with the request. Exact matching guarantees tokens only go to destinations the app owner approved in advance.

## Edge cases and pitfalls
- URL-encoded characters must match in encoded form. A path with %20 on one side and a space on the other is a mismatch.
- Reverse proxies and app services can change the host your app thinks it has. Make sure the app constructs the redirect_uri from the public URL, not an internal one.
- Wildcard redirect URIs are not allowed. Every URL must be listed explicitly, which is deliberate.
- Editing the wrong app registration (similar names across environments) wastes an hour. Verify the client ID matches your app's config before editing.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_HeUbxVzMBmvSxP1V7ZH1Uw
