OAuthAccountNotLinked 🔐 Authentication

NextAuth / Auth.js: OAuthAccountNotLinked — To confirm your identity, sign in with the same account you used originally

A user tried to sign in with a new OAuth provider using an email that already belongs to an account created with a different provider.

Seen on: REST API

Meaning

For security, Auth.js won’t automatically link accounts by email (could allow account takeover). Users must sign in with the original provider, or you enable linking only for providers that verify emails.

Common causes

  • Same email registered via another provider (Google vs GitHub vs email)
  • Account created via credentials/email link earlier

⚡ Quick fix

  1. Ask users to sign in with the original provider, then link accounts
  2. Set allowDangerousEmailAccountLinking only for trusted, email-verifying providers
  3. Show a clear message on the error page

Detailed fix by platform

JavaScript

  1. GoogleProvider({ clientId, clientSecret, allowDangerousEmailAccountLinking: true }) // only if you accept the trade-off

How to diagnose

  1. Accounts — Existing provider for that email
  2. Policy — Linking allowed?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.