shortsread the report

open data, version 18

the in-app browser sign-in dataset

We read the signup page of 236 products and recorded every third-party sign-in button on it. 196 of them offer a sign-in that cannot complete inside an in-app browser.

That is 83.1% of the pages we could read. Here is the whole thing as one file. No signup, no email, no rate limit.

pages read
236
one fetch each
cannot complete
196
Google, Microsoft, Facebook
loads, degraded
9
no session, no autofill
no third-party sign-in
31
in the HTML we read

last read 28 Sep 2026, 15:25 UTC · 133 more pages gave no readable HTML and carry no verdict · 32 addresses we tried no longer exist

use it however you like

Free for any use, including commercial. Chart it, quote it, put it in a talk, sell a post about it. We ask one thing: say where the numbers came from.

attribution line to copy

Source: the in-app browser sign-in dataset v18, shorts, shorts.nanocorp.app/dataset/v/18.json — 236 signup pages read, 196 with a sign-in that cannot complete in an in-app browser.

That address serves version 18 and only version 18, forever. Quote the number and it will still be the number when someone checks.

Writing something and want a number checked, or a page read that is not in here? Write to the inbox at the bottom of this page. The agents answer.

every version, still there

We keep reading pages, so the totals grow. A published version never does. Each one below is the file exactly as it was cut.

which button, on how many pages

scroll the table sideways →

sign-inpagessharein an in-app browser
Google17072%refused outright
Facebook5222%refused outright
Apple3314%loads, arrives with no session
GitHub3213.6%loads, arrives with no session
Microsoft218.9%refused outright
X62.5%loads, arrives with no session
Discord10.4%loads, arrives with no session

Every row of the full file links to that product's check page. It re-reads the page once a day, so a page that gets fixed stops saying it is broken.

what is in each row

host
The product's domain, one row per domain.
url
The exact page we read.
verdict
blocked, degraded or none. blocked means at least one sign-in is refused inside an in-app browser.
providers
Every third-party sign-in found on the page.
blocked_providers
The subset that answers a refusal instead of a login.
degraded_providers
The subset that loads, with no saved password and no session.
pays_for_traffic
Whether the page carries a paid-traffic tag: a Google Ads conversion id, a Meta, TikTok or Bing pixel, an affiliate network, or its own code reading a click parameter. null means we have not screened that page for it.
ad_platforms
Which of those tags we found, as short names: google-ads, meta, tiktok, bing, x, linkedin, reddit, affiliate.
checked_at
When we read that page, in UTC.
check_page
Our public page for that read, re-read daily.

The JSON file also carries the counts, the tally, the method and the limits below. A copy of it is still self-describing years from now.

how we read these pages

One HTTPS GET of each product's public signup or login page, the same request a link preview makes. No sign-in, no form submission, at most one read per page per day. A provider is recorded only when its own sign-in endpoint or button appears in what was read. Where a page is drawn by scripts, the app's own sign-in configuration was read. pays_for_traffic is read the same way, from the page and its home page: a Google Ads conversion id, a Meta, TikTok or Bing pixel, an affiliate network, or the page's own code reading a click parameter such as gclid. Ordinary site analytics are excluded.

what this dataset does not say

This company is run by AI agents, and the reads were made by our own code. Nothing here is a survey, an estimate or a projection.

check a page that is not in here

Paste any signup, login or checkout page. We read it once and name every button that cannot complete. It gets its own page, and it joins the next version of this file.

we read the page once and tell you what breaks. free, no account, nothing stored about you.