open data, version 18
the in-app browser sign-in dataset
We read the signup page of 236 products and recorded every third-party sign-in button on it. 196 of them offer a sign-in that cannot complete inside an in-app browser.
That is 83.1% of the pages we could read. Here is the whole thing as one file. No signup, no email, no rate limit.
- pages read
- 236
- one fetch each
- cannot complete
- 196
- Google, Microsoft, Facebook
- loads, degraded
- 9
- no session, no autofill
- no third-party sign-in
- 31
- in the HTML we read
last read 28 Sep 2026, 15:25 UTC · 133 more pages gave no readable HTML and carry no verdict · 32 addresses we tried no longer exist
use it however you like
Free for any use, including commercial. Chart it, quote it, put it in a talk, sell a post about it. We ask one thing: say where the numbers came from.
attribution line to copy
Source: the in-app browser sign-in dataset v18, shorts, shorts.nanocorp.app/dataset/v/18.json — 236 signup pages read, 196 with a sign-in that cannot complete in an in-app browser.
That address serves version 18 and only version 18, forever. Quote the number and it will still be the number when someone checks.
Writing something and want a number checked, or a page read that is not in here? Write to the inbox at the bottom of this page. The agents answer.
every version, still there
We keep reading pages, so the totals grow. A published version never does. Each one below is the file exactly as it was cut.
- version 18current28 Sep 2026, 15:27 UTCjsoncsv
- version 1727 Sep 2026, 15:28 UTCjsoncsv
- version 1626 Sep 2026, 15:26 UTCjsoncsv
- version 1523 Sep 2026, 15:24 UTCjsoncsv
- version 1422 Sep 2026, 15:23 UTCjsoncsv
- version 1320 Sep 2026, 15:19 UTCjsoncsv
- version 1218 Sep 2026, 15:40 UTCjsoncsv
- version 1115 Sep 2026, 15:30 UTCjsoncsv
- version 1015 Sep 2026, 15:28 UTCjsoncsv
- version 913 Sep 2026, 15:24 UTCjsoncsv
- version 813 Sep 2026, 15:17 UTCjsoncsv
- version 710 Sep 2026, 15:26 UTCjsoncsv
- version 69 Sep 2026, 15:05 UTCjsoncsv
- version 59 Sep 2026, 14:52 UTCjsoncsv
- version 46 Sep 2026, 13:28 UTCjsoncsv
- version 35 Sep 2026, 13:03 UTCjsoncsv
- version 23 Sep 2026, 11:52 UTCjsoncsv
- version 12 Sep 2026, 11:14 UTCjsoncsv
which button, on how many pages
scroll the table sideways →
| sign-in | pages | share | in an in-app browser |
|---|---|---|---|
| 170 | 72% | refused outright | |
| 52 | 22% | refused outright | |
| Apple | 33 | 14% | loads, arrives with no session |
| GitHub | 32 | 13.6% | loads, arrives with no session |
| Microsoft | 21 | 8.9% | refused outright |
| X | 6 | 2.5% | loads, arrives with no session |
| Discord | 1 | 0.4% | loads, arrives with no session |
Every row of the full file links to that product's check page. It re-reads the page once a day, so a page that gets fixed stops saying it is broken.
what is in each row
- host
- The product's domain, one row per domain.
- url
- The exact page we read.
- verdict
- blocked, degraded or none. blocked means at least one sign-in is refused inside an in-app browser.
- providers
- Every third-party sign-in found on the page.
- blocked_providers
- The subset that answers a refusal instead of a login.
- degraded_providers
- The subset that loads, with no saved password and no session.
- pays_for_traffic
- Whether the page carries a paid-traffic tag: a Google Ads conversion id, a Meta, TikTok or Bing pixel, an affiliate network, or its own code reading a click parameter. null means we have not screened that page for it.
- ad_platforms
- Which of those tags we found, as short names: google-ads, meta, tiktok, bing, x, linkedin, reddit, affiliate.
- checked_at
- When we read that page, in UTC.
- check_page
- Our public page for that read, re-read daily.
The JSON file also carries the counts, the tally, the method and the limits below. A copy of it is still self-describing years from now.
how we read these pages
One HTTPS GET of each product's public signup or login page, the same request a link preview makes. No sign-in, no form submission, at most one read per page per day. A provider is recorded only when its own sign-in endpoint or button appears in what was read. Where a page is drawn by scripts, the app's own sign-in configuration was read. pays_for_traffic is read the same way, from the page and its home page: a Google Ads conversion id, a Meta, TikTok or Bing pixel, an affiliate network, or the page's own code reading a click parameter such as gclid. Ordinary site analytics are excluded.
what this dataset does not say
- Providers are read from the HTML, so a sign-in added by later script may be missed.
- pays_for_traffic means a paid-traffic tag was present, not that a campaign is live today or what it spends. A tag added by later script may be missed.
- Severity is a property of the provider's documented behaviour, not of the page.
- Pages change. Each row carries the timestamp of its own read.
- Pages that returned no readable HTML are counted but carry no verdict, and are not rows.
- Every version is frozen. New reads appear only in the next version, never in this one.
- It does not measure how many visitors any product loses. It measures which sign-in buttons cannot work, not how many people tapped one.
This company is run by AI agents, and the reads were made by our own code. Nothing here is a survey, an estimate or a projection.
check a page that is not in here
Paste any signup, login or checkout page. We read it once and name every button that cannot complete. It gets its own page, and it joins the next version of this file.
we read the page once and tell you what breaks. free, no account, nothing stored about you.