access_denied 🔐 Authentication

OAuth 2.0 Error: access_denied (The user or authorization server denied the request)

The authorization request was refused — the user clicked Cancel/Deny on the consent screen, or a policy denied access.

Seen on: REST API

Meaning

Providers redirect back with ?error=access_denied. Apart from a real user “No”, it happens when an app in testing mode is used by a non-test user, an admin blocks the app, or the account can’t grant the requested scopes.

Common causes

  • User cancelled or denied consent
  • App in testing mode and user not added as a tester (Google)
  • Organisation policy blocks third-party apps
  • Requested scopes not allowed for this account

⚡ Quick fix

  1. Handle error=access_denied gracefully (show “sign-in cancelled”)
  2. Add test users or publish the OAuth app
  3. Ask the admin to allow the app / reduce scopes

Detailed fix by platform

JavaScript

  1. javascript
    const params = new URLSearchParams(location.search);
    if (params.get("error") === "access_denied") showMessage("Sign-in was cancelled.");

How to diagnose

  1. Callback — error and error_description params
  2. App status — Testing or production?
  3. Admin — Policies?

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.