Firebase Auth: auth/unauthorized-domain — This domain is not authorized for OAuth operations for your Firebase project
The site’s domain isn’t listed in Firebase Authentication → Settings → Authorized domains.
Seen on:
REST API
Meaning
Firebase allows OAuth popups/redirects only from authorized domains. New production domains, preview deployments (Vercel/Netlify URLs), or 127.0.0.1 vs localhost cause it.
Common causes
- Production/custom domain not added
- Preview deployment domains
- Using 127.0.0.1 instead of localhost
⚡ Quick fix
- Add the domain under Authentication → Settings → Authorized domains
- Use a stable preview domain
- Use localhost for local development
Detailed fix by platform
Firebase
# Console → Authentication → Settings → Authorized domains → Add domain
How to diagnose
- Host — window.location.hostname
- List — Authorized domains
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS500113 AADSTS500113: No reply address is registered for the application
- Access blocked: has not completed the Google verification process Google OAuth: Error 403: access_denied — The developer hasn't given you access to this app / has not completed the Google verification process
- access_denied OAuth 2.0 Error: access_denied (The user or authorization server denied the request)
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026