@sku are you by any chance using Regular Web Application
as your Application type? What is the Token Endpoint Authentication method for your app? It should be Single Page Application type and Token Endpoint Authentication Method should be set to None
.