OAuth 2.0 Error: access_denied (The user or authorization server denied the request)
The authorization request was refused — the user clicked Cancel/Deny on the consent screen, or a policy denied access.
Seen on:
REST API
Meaning
Providers redirect back with ?error=access_denied. Apart from a real user “No”, it happens when an app in testing mode is used by a non-test user, an admin blocks the app, or the account can’t grant the requested scopes.
Common causes
- User cancelled or denied consent
- App in testing mode and user not added as a tester (Google)
- Organisation policy blocks third-party apps
- Requested scopes not allowed for this account
⚡ Quick fix
- Handle error=access_denied gracefully (show “sign-in cancelled”)
- Add test users or publish the OAuth app
- Ask the admin to allow the app / reduce scopes
Detailed fix by platform
JavaScript
- javascript
const params = new URLSearchParams(location.search); if (params.get("error") === "access_denied") showMessage("Sign-in was cancelled.");
How to diagnose
- Callback — error and error_description params
- App status — Testing or production?
- Admin — Policies?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- AADSTS65001 AADSTS65001: The user or administrator has not consented to use the application
- Access blocked: has not completed the Google verification process Google OAuth: Error 403: access_denied — The developer hasn't given you access to this app / has not completed the Google verification process
- auth/popup-closed-by-user Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026