Google OAuth: Error 403: disallowed_useragent (sign-in from an embedded WebView)
Google blocks OAuth sign-in inside embedded WebViews (in-app browsers, Electron BrowserWindow, React Native WebView).
Seen on:
REST API
Meaning
Google requires the system browser or Custom Tabs/ASWebAuthenticationSession for OAuth. In-app browsers of social apps (Instagram, Facebook) also trigger it when users open your site there.
Common causes
- OAuth inside WKWebView/Android WebView/Electron
- Link opened in Instagram/Facebook/LinkedIn in-app browser
- Custom user agent spoofing
⚡ Quick fix
- Use AppAuth / ASWebAuthenticationSession / Custom Tabs
- In web apps, detect in-app browsers and ask users to open in the system browser
- Use Google’s native sign-in SDKs
Detailed fix by platform
Swift
- bash
let session = ASWebAuthenticationSession(url: authURL, callbackURLScheme: "com.example.app") { url, error in /* handle */ } session.presentationContextProvider = self session.start()
How to diagnose
- Context — WebView or system browser?
- Source — In-app browser of another app?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- access_denied OAuth 2.0 Error: access_denied (The user or authorization server denied the request)
- auth/popup-closed-by-user Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
- auth/unauthorized-domain Firebase Auth: auth/unauthorized-domain — This domain is not authorized for OAuth operations for your Firebase project
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026