Google OAuth: Error 403: access_denied — The developer hasn't given you access to this app / has not completed the Google verification process
The Google OAuth app is in “Testing” publishing status and the signing-in account isn’t listed as a test user.
Seen on:
REST API
Meaning
Apps in testing only allow listed test users (max 100) and refresh tokens expire after 7 days. Publishing to production (with verification if sensitive scopes are used) removes the limit.
Common causes
- Publishing status is Testing
- User not in test users list
- Sensitive/restricted scopes requiring verification
⚡ Quick fix
- Add the account under OAuth consent screen → Test users
- Publish the app (submit for verification if needed)
- Reduce scopes to non-sensitive ones
Detailed fix by platform
Google Cloud
- bash
# APIs & Services → OAuth consent screen → Audience → Test users → Add users # or Publish app → In production
How to diagnose
- Status — Testing or In production?
- Users — Listed?
- Scopes — Sensitive?
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- access_denied OAuth 2.0 Error: access_denied (The user or authorization server denied the request)
- auth/popup-closed-by-user Firebase Auth: auth/popup-closed-by-user / auth/popup-blocked / auth/cancelled-popup-request
- auth/unauthorized-domain Firebase Auth: auth/unauthorized-domain — This domain is not authorized for OAuth operations for your Firebase project
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026