Legacy Knowledge Base
Published Sep. 10, 2025

OAuth2 Token sometimes gets 401 response

Written By

Madeleine Clay

How To articles are not official guidelines or officially supported documentation. They are community-contributed content and may not always reflect the latest updates to Liferay DXP. We welcome your feedback to improve How To articles!

While we make every effort to ensure this Knowledge Base is accurate, it may not always reflect the most recent updates or official guidelines.We appreciate your understanding and encourage you to reach out with any feedback or concerns.

Legacy Article

You are viewing an article from our legacy "FastTrack" publication program, made available for informational purposes. Articles in this program were published without a requirement for independent editing or verification and are provided"as is" without guarantee.

Before using any information from this article, independently verify its suitability for your situation and project.

Issue

  • Sometimes users are unable to log in because their OAuth2 tokens receive a 401 "Unauthorized" response.
  • This seems to happen randomly, and the tokens should be valid.

Environment

  • Liferay DXP

Resolution

  • OAuth2 token authorization may fail if the token issue timestamp is slightly after the server's current timestamp
    • e.g. If the token is issued at 04:54:38.0 and the Liferay server timestamp is at 04:54:37.496.
  • This can happen if the servers aren't strictly time-synced.
  • If this is the cause of failure, it can be resolved by time-syncing the Liferay server with the OAuth2 token issuer server.

Additional Information

Your method for time-syncing servers will depend on your specific architecture, but below are some links to common third party resources on time-syncing.

Did this article resolve your issue ?

Legacy Knowledge Base