I can confirm the same issue independently with the official Home Assistant ViCare integration. I reproduced it today, 18 September 2026, with Home Assistant Core 2026.9.2. My Developer Portal client is configured according to the official Home Assistant ViCare documentation: Client name: HomeAssistant Google reCAPTCHA: disabled Redirect URI: https://my.home-assistant.io/redirect/oauth Public client / no client secret used The authorization/login succeeds and the OAuth callback reaches Home Assistant. The failure occurs specifically during the authorization-code/PKCE token exchange at: https://iam.viessmann-climatesolutions.com/idp/v3/token With OAuth debug logging enabled, Home Assistant reports: Token request for vicare_... failed (400): invalid_grant: Invalid grant I have reproduced the complete OAuth flow several times with fresh authorization codes and always get the same result. I also deleted and recreated the Home Assistant OAuth application credentials, freshly copied the Client ID from the Viessmann Developer Portal, verified the redirect URI and reCAPTCHA setting, and restarted Home Assistant. The result remains unchanged. This therefore appears to reproduce the same authorization-code/PKCE token-exchange problem described in the original post, using a completely independent implementation (the official Home Assistant ViCare integration). Could Viessmann please investigate whether there is currently an issue with the PKCE authorization-code exchange at the /idp/v3/token endpoint? I can provide additional debug information privately if required.
... Mehr anzeigen