This "retry with a new valid code or use an existing refresh token" seems to be related to the application server. If you're using IBM WebSphere, I would recommend opening a case with them. Someone from their Security team can look at the proper logs generated by WebSphere with SSO flags on.
This error does not seem to be related to the TRIRIGA SSO Configuration itself. I hope this helps.
------------------------------
Giuliano Schmidt
------------------------------