NextAuth / Auth.js: OAuthAccountNotLinked — To confirm your identity, sign in with the same account you used originally
A user tried to sign in with a new OAuth provider using an email that already belongs to an account created with a different provider.
Seen on:
REST API
Meaning
For security, Auth.js won’t automatically link accounts by email (could allow account takeover). Users must sign in with the original provider, or you enable linking only for providers that verify emails.
Common causes
- Same email registered via another provider (Google vs GitHub vs email)
- Account created via credentials/email link earlier
⚡ Quick fix
- Ask users to sign in with the original provider, then link accounts
- Set allowDangerousEmailAccountLinking only for trusted, email-verifying providers
- Show a clear message on the error page
Detailed fix by platform
JavaScript
GoogleProvider({ clientId, clientSecret, allowDangerousEmailAccountLinking: true }) // only if you accept the trade-off
How to diagnose
- Accounts — Existing provider for that email
- Policy — Linking allowed?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- access_denied OAuth 2.0 Error: access_denied (The user or authorization server denied the request)
- auth/popup-closed-by-user Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
- auth/unauthorized-domain Firebase Auth: auth/unauthorized-domain — This domain is not authorized for OAuth operations for your Firebase project
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026