WebAuthn / Passkeys: NotAllowedError: The operation either timed out or was not allowed
The browser refused the passkey/WebAuthn ceremony — the user cancelled, it timed out, no matching credential, or the call wasn’t triggered by a user gesture.
Seen on:
REST API
Meaning
The error is deliberately vague for privacy. Common causes: user dismissed the dialog, allowCredentials lists credentials not on this device, requests from iframes without permissions, or calling navigator.credentials.get without a click.
Common causes
- User cancelled or timeout expired
- No matching credential on this device
- Called without a user gesture or in a cross-origin iframe
- Platform authenticator not available
⚡ Quick fix
- Treat it as cancellation and offer retry/other methods
- Use discoverable credentials (empty allowCredentials) for passkeys
- Trigger from a button click; set publickey-credentials permissions for iframes
Detailed fix by platform
JavaScript
- javascript
try { await navigator.credentials.get({ publicKey: options }); } catch (e) { if (e.name === "NotAllowedError") showMessage("Passkey sign-in was cancelled or timed out."); }
How to diagnose
- Trigger — User gesture?
- Credentials — Exist on this device?
- Context — Iframe/origin
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- access_denied OAuth 2.0 Error: access_denied (The user or authorization server denied the request)
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
- Illegal arguments: undefined, string bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026