Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
Firebase rejected the email/password sign-in — wrong password, no such user, or a provider credential that’s malformed/expired.
Seen on:
REST API
Meaning
With email enumeration protection enabled (default for new projects), Firebase returns auth/invalid-credential instead of wrong-password/user-not-found. It also appears for expired OAuth credentials passed to signInWithCredential.
Common causes
- Wrong email or password
- User doesn’t exist (masked by enumeration protection)
- Account created with Google/another provider, not password
- Expired/invalid OAuth credential
⚡ Quick fix
- Show a generic “email or password incorrect” message
- Offer password reset / provider sign-in
- Check which providers the account uses
Detailed fix by platform
JavaScript
- javascript
try { await signInWithEmailAndPassword(auth, email, password); } catch (e) { if (e.code === "auth/invalid-credential") setError("Email or password is incorrect."); }
How to diagnose
- Account — Exists? Which providers?
- Credential — Fresh?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026