F5 Sites
  • F5.com
  • LearnF5
  • NGINX
  • MyF5
  • Partner Central
Contact
  • Under Attack?
  • F5 Support
  • DevCentral Support
  • F5 Sales
  • NGINX Sales
  • F5 Professional Services
Skip to contentBrand Logo
Forums
CrowdSRC
Articles
Groups
EventsSuggestionsHow Do I...?
RegisterSign In
  1. DevCentral
  2. Articles
  3. Technical Articles

Access Troubleshooting: BIG-IP APM OIDC integration

Table of Contents Introduction Implementation and troubleshooting Check the logs Case 1: Connection reset after authentication Troubleshooting steps: Case 2: Expired JWT Key...
Published Jul 08, 2024
Version 1.0
application delivery
devops
security
series-f5-access-security
Verified Designs
momahdy's avatar
momahdy
Icon for Employee rankEmployee
Principal Technical Marketing Engineer - Focus on BIG-IP
View Profile
DevBabu's avatar
DevBabu
Icon for Cirrus rankCirrus
Jun 05, 2025

Thank you for the article. In my case I am getting 'session.oauth.scope.last.errMsg' set to 'Invalid JWS token'. What would be the reason for this error message. I took packet capture, grabbed id token provided by IDP. It is valid.

  • momahdy's avatar
    momahdy
    Icon for Employee rankEmployee
    Jun 06, 2025

    It seems the challenge in how scope (Server) confirm the JWS, so may be check the assigned server in the VPE, also check if you are performing internal / external validation try to explore both to match what works better for your deployment.

ABOUT DEVCENTRAL

DevCentral NewsTechnical ForumTechnical ArticlesTechnical CrowdSRCCommunity GuidelinesDevCentral EULAGet a Developer Lab LicenseBecome a DevCentral MVP

RESOURCES

Product DocumentationWhite PapersGlossaryCustomer StoriesWebinarsFree Online CoursesF5 CertificationLearnF5 Training

SUPPORT

Manage SubscriptionsProfessional ServicesProfessional ServicesCreate a Service RequestSoftware DownloadsSupport Portal

PARTNERS

Find a Reseller PartnerTechnology AlliancesBecome an F5 PartnerLogin to Partner Central

F5 logo©2024 F5, Inc. All rights reserved.
TrademarksPoliciesPrivacyCalifornia PrivacyDo Not Sell My Personal Information