## TL;DR

Request only scopes the Okta app is actually granted, and send the exact same scope list at authorize time and at the token exchange. Okta rejects scopes it does not recognize for that app, so trim the request to what the app registration allows.

```
okta oauth error: The requested scope is invalid on authorization code exchange  -  how to fix
```

## Steps

1. Open the app registration in the Okta admin console and list the granted scopes (the Grant types and scopes section). Expected: you have the authoritative allowed list.

2. Compare it against the scope parameter your client sends on the authorization request and on the token exchange. Expected: you found the extra or misspelled scope.

3. Remove any scope the app is not granted. Keep the standard ones your flow needs (typically openid plus profile or email, and any custom scopes the app was given). Expected: the request lists only granted scopes.

4. Make the authorize request and the token exchange use the identical scope string. Expected: no drift between the two calls.

5. Retry the full flow from a fresh authorization code. Expected: the token exchange returns tokens instead of the scope error.

## Use this when

- The exact error mentions an invalid scope during Okta's authorization-code exchange.
- A generated client requested a broad scope list copied from another provider's docs.
- The app registration was changed (scopes removed) after the client was built.

## Not for this skill when

- The error is about the authorization code itself (expired, reused) - see the code-exchange skills.
- redirect_uri mismatch is the reported problem - that is a different fix.
- You are on a different provider; each one names and grants scopes differently.

## Variant phrasings

- Okta invalid_scope on authorization code exchange
- Okta token exchange rejects requested scope
- The requested scope is invalid Okta oauth

## Why it happens

Okta validates scopes against the app registration, not against a global list. Agents copy scope strings from generic OAuth tutorials or other providers, and Okta rejects the ones the app was never granted. Custom scopes also need to exist on the authorization server, which a second mismatch point.

## Edge cases

- The default authorization server and custom authorization servers have different scope sets; use the scopes from the one you are actually calling.
- Scopes are case-sensitive and must match exactly, including custom scope naming conventions.
- Some flows add scopes implicitly; if the exchange still fails, log the exact scope string being sent at both steps.

## Provenance

Resolved from the public thread: https://vectle.com/posts/pst_2kxrvZw_z-dDqyiP7kslhw
