instagram · sign in with google
Instagram google login not working
Your visitor taps your link in an Instagram bio or story. They tap sign in with Google. Then nothing happens.
Usually there is no error to read. The screen turns white after they submit their password, and they close the tab.
The cause is not your code. Instagram opened your page in its own browser, and Google will not sign anyone in there.
“The whole screen turns completely white” after the user submits their Google credentials.
firebase-js-sdk issue 4421, “Google sign-in not working in Instagram in-app browser”
In other browsers the same refusal is legible: Error 403, disallowed_useragent. Instagram just goes blank, so nobody knows what to search.
why it happens
Instagram does not hand your link to Chrome or Safari. It renders your page inside a browser it embeds in its own app.
Google has refused OAuth in embedded browsers since 30 September 2021. The policy is one sentence and has no exception for a browser you did not choose.
A developer must not direct a Google OAuth 2.0 authorization request to an embedded user-agent under the developer’s control.
Google’s reason is that whoever embeds a browser can read what is typed into it. That reason is not hypothetical here.
In August 2022 Felix Krause published what Instagram’s in-app browser injects into third-party pages, using a page that logs the injection. Instagram was injecting script into every site it opened.
So the block is Google enforcing a rule against a browser that does, in fact, sit between your page and your visitor.
the same page, three browsers
- Instagram's in-app browsergoogle sign-in refused; usually a white screen, no error
- Chrome or Safari on the same phonesigns in normally, with the session and passwords already there
- your own app's WebViewalso refused, and Google documents the fix for that case
what it costs you
This failure is quiet, which is what makes it expensive. Nothing errors on your server and nothing appears in your logs.
A visitor who cannot sign in does not file a report. They close Instagram’s tab, and your analytics records a bounce.
Two things are hidden at once. The signup never happens, and the referrer that would have told you where they came from is stripped by the same browser.
So the post that did work and the post that did nothing look identical in your dashboard, and the sign-in that broke looks like disinterest.
what does not work
These are the answers people find first. Each one is either stale or fixes a different problem.
spoofing the user-agent string
The most-upvoted answers set a Chrome user-agent. Google reads more than that string now, and commenters on those same answers report the refusal unchanged.
signInWithRedirect instead of signInWithPopup
Do it anyway: a popup cannot open in a single-tab in-app browser. But Google answers the redirect with disallowed_useragent too, so sign-in still fails.
window.open to a chrome: or custom scheme on page load
Reported as not working from inside the embedded browser. Chrome's own documentation says a script with no user tap behind it will not launch another app.
hiding the Google button when you detect Instagram
This stops a broken button being shown, and Pinterest is cited as doing it. The visitor still loses the sign-in method they came to use.
asking the visitor to use the open-in-browser menu
Instagram does ship this menu, behind three dots in the corner of someone else's app. It works when found. Most people do not go looking.
The pattern is the same in all five. By the time your page is rendering, the browser is already the wrong one.
what works
There are two real fixes, and which applies depends on who opened the browser.
if your own app embeds the browser
use the platform's real browser component
Google names the replacements. On Android, open sign-in in Android Custom Tabs instead of a WebView. On iOS, use SFSafariViewController rather than WKWebView.
Both are the phone’s browser with your app around it, so the refusal stops.
It changes nothing for taps arriving from Instagram, because that browser is not yours.
if your taps arrive from instagram
escape at the link, before your page loads
The tap on your link is the one user gesture you get. A link that resolves on a server can use it to hand the destination to Chrome or Safari.
Your page then renders where the visitor’s Google session and saved passwords already are, and the button behaves normally.
This is the only fix available when someone else owns the browser.
Plainly: the second fix is what shorts is. We built it because we had the problem, and this page is accurate whether or not you use it.
You can build it yourself. The parts are a redirect that resolves server-side, per-platform escape handling, and somewhere to count the taps.
does your own signup page have this problem
Paste your signup or login page. We read it once and name every sign-in button that cannot complete inside an in-app browser. No account.
we read the page once and tell you what breaks. free, no account, nothing stored about you.
We read the signup pages of well-known products the same way, and most offer a sign-in that cannot complete there. That is the report.
A shorts link does the escape and counts every tap by source app. free keeps 5 links and 30 days of taps. shorts Lifetime is $49 once, with nothing recurring.
sources
Every claim above comes from one of these. Read them rather than taking our word.
- firebase-js-sdk issue 4421: Google sign-in in the Instagram in-app browserthe white screen, and the popup versus redirect distinction
- Google, OAuth 2.0 policies: use secure browsersthe policy sentence quoted above
- Google, security changes to the OAuth endpoint in embedded webviewsthe 30 September 2021 enforcement date, and the Custom Tabs and SFSafariViewController guidance
- Felix Krause: announcing InAppBrowser.comwhat Instagram's in-app browser injects, and that Instagram does offer an open-in-browser option
- r/Supabase: google authentication not working in Instagramthe same failure, reported by a developer using a different stack
- Auth0 community: google connect warning on Instagram appand again on a hosted identity provider
- how to avoid 403 disallowed_useragent from a third-party appthe 2023 thread whose accepted answer is to turn Google sign-in off
- Chrome, Android intentswhy a script with no tap behind it cannot open another browser
written 26 Aug 2026 · corrections to shorts@nanocorp.app
short answers
- Why does sign in with Google do nothing inside Instagram?
- Google refuses to run its sign-in flow in an embedded browser, and Instagram opens every link in one. Inside Instagram the refusal often renders as a white screen rather than an error.
- Is this a bug in my site?
- No. The same page signs people in normally in Chrome or Safari. The browser is the variable, not your code.
- Why do I see no error message?
- Developers report the screen turning white after the visitor submits their Google password. The 403 text appears in some browsers and not in Instagram's.
- Can I tell visitors to open the page in Safari?
- Instagram does have that menu, behind the three dots. It works, and most visitors will not find it or use it.
- What actually fixes it?
- The link has to leave Instagram's browser before your page loads. Nothing running inside that browser can move the visitor out of it.
- Does switching to a redirect flow fix it?
- It fixes a different failure, the popup that cannot open in a single-tab browser. Google still refuses the redirect with disallowed_useragent.
the other answers
Same mechanism, different app. Each page is sourced separately.
- Error 403: disallowed_useragentGoogle blocks OAuth in every embedded browser, so sign-in fails inside Instagram and TikTok. What the error means, what does not fix it, and what does.
- Facebook in-app browser OAuthTwo separate failures hit OAuth inside Facebook and Messenger: Google's embedded-browser block, and a popup that cannot open in a single-tab browser.
- TikTok browser sign inTikTok opens every link in its own browser, and Google refuses to sign anyone in there. TikTok is also the one app with no open-in-browser button.
All of them are listed on the answers page.