NotAllowedError (WebAuthn) 🔐 Authentication

WebAuthn / Passkeys: NotAllowedError: The operation either timed out or was not allowed

The browser refused the passkey/WebAuthn ceremony — the user cancelled, it timed out, no matching credential, or the call wasn’t triggered by a user gesture.

Seen on: REST API

Meaning

The error is deliberately vague for privacy. Common causes: user dismissed the dialog, allowCredentials lists credentials not on this device, requests from iframes without permissions, or calling navigator.credentials.get without a click.

Common causes

  • User cancelled or timeout expired
  • No matching credential on this device
  • Called without a user gesture or in a cross-origin iframe
  • Platform authenticator not available

⚡ Quick fix

  1. Treat it as cancellation and offer retry/other methods
  2. Use discoverable credentials (empty allowCredentials) for passkeys
  3. Trigger from a button click; set publickey-credentials permissions for iframes

Detailed fix by platform

JavaScript

  1. javascript
    try { await navigator.credentials.get({ publicKey: options }); }
    catch (e) { if (e.name === "NotAllowedError") showMessage("Passkey sign-in was cancelled or timed out."); }

How to diagnose

  1. Trigger — User gesture?
  2. Credentials — Exist on this device?
  3. Context — Iframe/origin

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.