invalid_redirect_uri
Every
redirect_uri used at /authorize and /oauth/token must be
byte-identical to one registered via DCR. URIs must be HTTPS
(http://localhost allowed for development; custom schemes allowed for
native clients).
Re-register with the correct URI list if yours has changed.