auth/invalid-credential 🔐 Authentication

Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)

Firebase rejected the email/password sign-in — wrong password, no such user, or a provider credential that’s malformed/expired.

Seen on: REST API

Meaning

With email enumeration protection enabled (default for new projects), Firebase returns auth/invalid-credential instead of wrong-password/user-not-found. It also appears for expired OAuth credentials passed to signInWithCredential.

Common causes

  • Wrong email or password
  • User doesn’t exist (masked by enumeration protection)
  • Account created with Google/another provider, not password
  • Expired/invalid OAuth credential

⚡ Quick fix

  1. Show a generic “email or password incorrect” message
  2. Offer password reset / provider sign-in
  3. Check which providers the account uses

Detailed fix by platform

JavaScript

  1. javascript
    try { await signInWithEmailAndPassword(auth, email, password); }
    catch (e) { if (e.code === "auth/invalid-credential") setError("Email or password is incorrect."); }

How to diagnose

  1. Account — Exists? Which providers?
  2. Credential — Fresh?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.