Box oauth2: Invalid grant_type parameter or parameter missing
Box oauth2: Invalid grant_type parameter or parameter missing. Looks like Box requires a correct Content-Type: application/x-www-form-urlencoded request header in addition to properly URL encoding the parameters. Use when hitting this exact issue with Box oauth2. Not for unrelated errors or different features.
TL;DR
Looks like Box requires a correct Content-Type: application/x-www-form-urlencoded request header in addition to properly URL encoding the parameters. The same seems to apply to refresh and revoke requests.
The error
Invalid grant_type parameter or parameter missingFix
- Looks like Box requires a correct Content-Type: application/x-www-form-urlencoded request header in addition to properly URL encoding the parameters.
Expected: You get the expected result; the problem is gone.
- The same seems to apply to refresh and revoke requests.
Expected: You get the expected result; the problem is gone.
- Also, per RFC 6749, the redirecturi is only REQUIRED, if the "redirecturi" parameter was included in the authorization request as described in Section 4.1.1, and their values MUST be identical.
Expected: You get the expected result; the problem is gone.
- Re-run the original operation and confirm the error is gone.
Expected: no error, normal output.
When to use
- You hit this exact error with Box oauth2.
- The symptom matches: Invalid grant_type parameter or parameter missing.
When NOT to use
- A different error message from Box oauth2; the cause here is specific to this error.
- Unrelated Box oauth2 issues (different feature, different failure).
- You need general documentation for the tool; check the official docs instead.
Compatibility
Reported against Box oauth2 (mentions 4.1.1).
Variant phrasings
Invalid grant_type parameter or parameter missing
Why it happens
Stack Overflow question (score 11, has accepted answer): Exchanging the authorization code for tokens at the Box token endpoint keeps returning 400 "Invalid granttype parameter or parameter missing", even though granttype, code, clientid and clientsecret are all being posted as form fields.
Edge cases
- If your error message differs even slightly, this is probably a different issue; search the exact text.
- Behavior can change between releases; the linked source reflects the versions above.
- If the fix does not help, capture the full error output and check the source link for updates.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.