WebAuthn: SecurityError: The relying party ID is not a registrable domain suffix of, nor equal to the current domain
The rp.id in the WebAuthn options doesn’t match the page’s domain (or a parent domain), so the browser rejects it.
Seen on:
REST API
Meaning
rp.id must equal the current hostname or a registrable suffix (example.com for app.example.com). Using a different domain, a full URL, a port, or localhost mismatches cause this. Related origins require explicit configuration.
Common causes
- rp.id set to another domain
- Including scheme/port in rp.id
- Testing on a different host than configured (IP vs localhost)
- Server config for production used in staging
⚡ Quick fix
- Set rp.id to the current domain or its parent
- Use hostname only (no https://, no port)
- Configure per-environment RP IDs
Detailed fix by platform
JavaScript
const options = { rp: { id: "example.com", name: "Example" }, /* ... */ }; // page on app.example.com
How to diagnose
- Host — window.location.hostname
- RP ID — Value sent by the server
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- auth/invalid-credential Firebase Auth: auth/invalid-credential (auth/wrong-password, auth/user-not-found, auth/invalid-login-credentials)
- auth/network-request-failed Firebase Auth: auth/network-request-failed — A network AuthError (such as timeout, interrupted connection or unreachable host) has occurred
- Illegal arguments: undefined, string bcrypt error: Illegal arguments: undefined, string / data and salt arguments required / data and hash arguments required
Most viewed in Authentication
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026