Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
The OAuth popup for Google/GitHub sign-in was closed, blocked by the browser, or replaced by another popup request.
Seen on:
REST API
Meaning
Popups must open from a direct user click. Browsers block them otherwise, mobile/in-app browsers handle them poorly, and Cross-Origin-Opener-Policy headers can break the popup communication.
Common causes
- User closed the popup
- signInWithPopup not called directly in a click handler
- Popup blocker / in-app browser
- COOP header same-origin breaking popup messaging
⚡ Quick fix
- Call signInWithPopup directly from the click handler
- Fall back to signInWithRedirect on mobile
- Use Cross-Origin-Opener-Policy: same-origin-allow-popups
Detailed fix by platform
JavaScript
- javascript
button.onclick = async () => { try { await signInWithPopup(auth, provider); } catch (e) { if (e.code === "auth/popup-blocked") await signInWithRedirect(auth, provider); } };
How to diagnose
- Trigger — Inside click handler?
- Browser — Popup blocker / in-app?
- Headers — COOP value
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS500113 AADSTS500113: No reply address is registered for the application
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
- Access blocked: has not completed the Google verification process Google OAuth: Error 403: access_denied — The developer hasn't given you access to this app / has not completed the Google verification process
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026