You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Next-Auth自定义OIDC PKCE认证报错:client_secret_basic需client_secret

问题:NextAuth自定义OIDC PKCE流触发client_secret认证错误

环境:Next.js 13.4.19、Node.js 18.12.1
在next-auth-example项目中,因重复路由删除了app/api/auth/[...nextauth],配置自定义OIDC PKCE流的OAuth Provider后,认证流程收尾阶段触发[next-auth][error][OAUTH_CALLBACK_ERROR],提示“client_secret_basic client authentication method requires a client_secret”,但该PKCE凭证本身无client_secret。

配置代码:

{
  id:"Umar",
  name: "umarPKCTNextAuth",
  type: "oauth",

  wellKnown:"https://auth.folderit.com/.well-known/openid-configuration",
  checks: ["pkce","state"],
  idToken: true,
  clientId: process.env.AUTH0_ID,

  authorization: { params: { scope: "openid" } },
  profile(profile: { id: any; kakao_account: { profile: { nickname: any; profile_image_url: any }; email: any } }) {
    return {
      id: profile.id,
      name: profile.kakao_account?.profile.nickname,
      email: profile.kakao_account?.email,
      image: profile.kakao_account?.profile.profile_image_url,
    }
  }
},
解决方案
  • 显式指定客户端认证方法为none
    PKCE流程不需要client_secret,需在Provider配置中添加clientAuthMethod: "none",告知NextAuth不要使用默认的client_secret_basic认证方式:
{
  id:"Umar",
  name: "umarPKCTNextAuth",
  type: "oauth",

  wellKnown:"https://auth.folderit.com/.well-known/openid-configuration",
  checks: ["pkce","state"],
  idToken: true,
  clientId: process.env.AUTH0_ID,
  clientAuthMethod: "none", // 新增该行配置
  authorization: { params: { scope: "openid" } },
  profile(profile: { id: any; kakao_account: { profile: { nickname: any; profile_image_url: any }; email: any } }) {
    return {
      id: profile.id,
      name: profile.kakao_account?.profile.nickname,
      email: profile.kakao_account?.email,
      image: profile.kakao_account?.profile.profile_image_url,
    }
  }
},
  • 确认OIDC提供商的PKCE支持配置
    访问https://auth.folderit.com/.well-known/openid-configuration,查看token_endpoint_auth_methods_supported是否包含none。如果不包含,需在提供商后台将该客户端的认证方式设置为PKCE(无client_secret)。

  • 恢复必要的路由文件
    删除app/api/auth/[...nextauth]可能导致NextAuth回调路由失效,建议恢复该文件以保证路由正常:

// app/api/auth/[...nextauth]/route.ts
import NextAuth from "next-auth";
import { authOptions } from "@/lib/auth"; // 替换为你的auth配置文件路径

const handler = NextAuth(authOptions);

export { handler as GET, handler as POST };

内容的提问来源于stack exchange,提问作者Muhammad Umar Khan

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.11 00:09:58