auth/popup-closed-by-user 🔐 Authentication

Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request

The OAuth popup for Google/GitHub sign-in was closed, blocked by the browser, or replaced by another popup request.

Seen on: REST API

Meaning

Popups must open from a direct user click. Browsers block them otherwise, mobile/in-app browsers handle them poorly, and Cross-Origin-Opener-Policy headers can break the popup communication.

Common causes

  • User closed the popup
  • signInWithPopup not called directly in a click handler
  • Popup blocker / in-app browser
  • COOP header same-origin breaking popup messaging

⚡ Quick fix

  1. Call signInWithPopup directly from the click handler
  2. Fall back to signInWithRedirect on mobile
  3. Use Cross-Origin-Opener-Policy: same-origin-allow-popups

Detailed fix by platform

JavaScript

  1. javascript
    button.onclick = async () => {
      try { await signInWithPopup(auth, provider); }
      catch (e) { if (e.code === "auth/popup-blocked") await signInWithRedirect(auth, provider); }
    };

How to diagnose

  1. Trigger — Inside click handler?
  2. Browser — Popup blocker / in-app?
  3. Headers — COOP value

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.