relying party ID is not a registrable domain suffix 🔐 Authentication

WebAuthn: SecurityError: The relying party ID is not a registrable domain suffix of, nor equal to the current domain

The rp.id in the WebAuthn options doesn’t match the page’s domain (or a parent domain), so the browser rejects it.

Seen on: REST API

Meaning

rp.id must equal the current hostname or a registrable suffix (example.com for app.example.com). Using a different domain, a full URL, a port, or localhost mismatches cause this. Related origins require explicit configuration.

Common causes

  • rp.id set to another domain
  • Including scheme/port in rp.id
  • Testing on a different host than configured (IP vs localhost)
  • Server config for production used in staging

⚡ Quick fix

  1. Set rp.id to the current domain or its parent
  2. Use hostname only (no https://, no port)
  3. Configure per-environment RP IDs

Detailed fix by platform

JavaScript

  1. const options = { rp: { id: "example.com", name: "Example" }, /* ... */ }; // page on app.example.com

How to diagnose

  1. Host — window.location.hostname
  2. RP ID — Value sent by the server

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.