CLEARTEXT 🤖 Android

CLEARTEXT communication to host not permitted by network security policy

Android 9+ blocks plain http:// requests by default; the app tried to call a non-HTTPS URL.

Seen on: Android

Meaning

Since API 28, cleartext traffic is disabled unless explicitly allowed. It typically hits local development servers (http://10.0.2.2:3000) or old APIs without TLS.

Common causes

  • API base URL uses http://
  • Local dev server accessed over HTTP from emulator/device
  • Third-party SDK calling an HTTP endpoint
  • Redirect from https to http

⚡ Quick fix

  1. Use HTTPS for production APIs
  2. For development only, allow cleartext for specific hosts via network security config
  3. Avoid android:usesCleartextTraffic="true" app-wide in release builds

Detailed fix by platform

Android

  1. res/xml/network_security_config.xml (debug hosts only):
    xml
    <network-security-config>
        <domain-config cleartextTrafficPermitted="true">
            <domain includeSubdomains="false">10.0.2.2</domain>
            <domain includeSubdomains="false">localhost</domain>
        </domain-config>
    </network-security-config>
    <!-- AndroidManifest: <application android:networkSecurityConfig="@xml/network_security_config" … > -->

How to diagnose

  1. URL — Which host/URL is http?
  2. Build — Debug only or also release?
  3. Redirects — Any https→http redirect?

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.