microsoft graph oauth aaddsts50011 redirect uri mismatch error
For developers and agents wiring Microsoft logins. Use when AADSTS50011 blocks login. Not for token or consent errors.
Fix Microsoft Graph OAuth AADSTS50011 redirect URI mismatch
TL;DR
AADSTS50011 means the redirect URI your app sent is not registered on the Entra app registration. Copy the exact redirect URI from the error and add it to the app registration's redirect URIs. Entra compares them exactly, so mind trailing slashes.
The error
AADSTS50011: The redirect URI specified in the request does not match the redirect URIs configured for the application.Use this skill
Agent? Search Vectle for this error:
curl -s "https://vectle.com/api/v1/search?q=microsoft graph oauth aaddsts50011 redirect uri mismatch error"Fix it
Step 1: Copy the redirect URI from the error page
Reproduce the login and copy the redirect_uri value shown in the AADSTS50011 error detail.Expected: You have the exact URI the app sent.
Step 2: Open the app registration in Entra
Entra admin center -> Identity -> Applications -> App registrations -> [app] -> Authentication.Expected: You see the registered redirect URIs list.
Step 3: Add the exact URI
Add the copied URI to the list, matching scheme, host, path, and trailing slash exactly, then save.Expected: The URI appears in the list and saves without errors.
Step 4: Check the platform type
Make sure the URI is registered under the right platform (Web versus Single-page application).Expected: The URI sits under the correct platform section.
Step 5: Retry the login
Run the OAuth flow again.Expected: Login completes without AADSTS50011.
When this applies
- Microsoft Graph or Entra logins fail with AADSTS50011
- You added a new environment or changed the app URL
- The app worked locally but fails when deployed
When it doesn't
- The error is AADSTS70011 or another code (different condition)
- The redirect works but tokens are rejected (check the token config)
- You are using device code flow (no redirect URI involved)
Compatibility
Microsoft Entra ID OAuth 2.0 and OpenID Connect. App registrations as of 2026.
Variant phrasings
aadsts50011 redirect uri mismatch fix
Same error. The error page shows the offending URI; trust it over your config memory.
microsoft oauth reply url does not match
Reply URL is the older name for redirect URI. Same list, same exact-match rule.
aadsts50011 dev-machine versus production
Dev-machine URIs registered for local testing do not cover production. Register each environment separately.
Why it happens
Entra only redirects to pre-registered URIs as an anti-phishing control, and it compares them as exact strings. A deploy that changes the path, a missing trailing slash, or an http/https swap all produce AADSTS50011. The app changed; the registration did not follow.
Edge cases
- Single-page apps must register under the SPA platform or silent token renewal breaks
- Wildcard redirect URIs are not allowed; register each URI explicitly
- After adding the URI, wait a minute for propagation before retesting
If it still fails
- Reproduce with one API call in isolation, outside the agent, to separate platform issues from agent issues.
- Check the platform status page and changelog; OAuth and webhook behaviors change without warning.
- Capture the full request and response with timestamps for the vendor ticket, redacting credentials.
- Test in a second workspace or sandbox to rule out workspace-specific policy blocks.
- If the integration is business-critical, build the fallback now: cached data, a manual trigger, or a second provider.
Prevention
- Store OAuth credentials in a secrets manager with rotation reminders.
- Build the reconnect flow before you need it; every integration gets revoked eventually.
- Log token ages so expiring grants are visible ahead of time.
- Keep a sandbox integration for testing config changes.
- Document the required scopes per integration so reinstalls request the right ones.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_S0JHqYI10ztXRy40MzPryA
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.