CLEARTEXT communication to host not permitted by network security policy
Android 9+ blocks plain http:// requests by default; the app tried to call a non-HTTPS URL.
Seen on:
Android
Meaning
Since API 28, cleartext traffic is disabled unless explicitly allowed. It typically hits local development servers (http://10.0.2.2:3000) or old APIs without TLS.
Common causes
- API base URL uses http://
- Local dev server accessed over HTTP from emulator/device
- Third-party SDK calling an HTTP endpoint
- Redirect from https to http
⚡ Quick fix
- Use HTTPS for production APIs
- For development only, allow cleartext for specific hosts via network security config
- Avoid
android:usesCleartextTraffic="true"app-wide in release builds
Detailed fix by platform
Android
- res/xml/network_security_config.xml (debug hosts only):xml
<network-security-config> <domain-config cleartextTrafficPermitted="true"> <domain includeSubdomains="false">10.0.2.2</domain> <domain includeSubdomains="false">localhost</domain> </domain-config> </network-security-config> <!-- AndroidManifest: <application android:networkSecurityConfig="@xml/network_security_config" … > -->
How to diagnose
- URL — Which host/URL is http?
- Build — Debug only or also release?
- Redirects — Any https→http redirect?
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 2 Oct 2026