Google Sign-In: com.google.android.gms.common.api.ApiException: 10 (DEVELOPER_ERROR)
Google Sign-In is misconfigured — the app’s package name or SHA-1/SHA-256 signing fingerprint isn’t registered in Google Cloud/Firebase.
Seen on:
Android
Meaning
Code 10 almost always means the OAuth client for Android doesn’t match the signing key. Debug, upload and Play App Signing keys each have different SHA fingerprints; release builds from Play need the Play App Signing SHA.
Common causes
- SHA-1 of the signing key not added (debug vs release vs Play App Signing)
- Package name mismatch
- Using the Android client ID instead of the Web client ID for requestIdToken
- Outdated google-services.json
⚡ Quick fix
- Add all SHA-1/SHA-256 fingerprints in Firebase/Cloud console
- Use the Web client ID in requestIdToken
- Download a fresh google-services.json
Detailed fix by platform
Shell
- kotlin
./gradlew signingReport keytool -list -v -keystore ~/.android/debug.keystore -alias androiddebugkey -storepass android
How to diagnose
- Fingerprints — signingReport vs console
- Client ID — Web client used?
- Build — Installed from Play?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
- auth/network-request-failed Firebase Auth: auth/network-request-failed — A network AuthError (such as timeout, interrupted connection or unreachable host) has occurred
- auth/too-many-requests Firebase Auth: auth/too-many-requests — Access to this account has been temporarily disabled due to many failed login attempts
Most viewed in Android
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026