Prompt
Google login callback not working after deploy
Latest observation
Oct 6, 2026
OpenAI APIWeb search: off
This usually comes down to redirect URI / OAuth config mismatch between local and production.
Quick checklist
1) Verify the Google OAuth redirect URI in Google Cloud Console
In APIs & Services → Credentials → OAuth 2.0 Client IDs, make sure your Authorized redirect URI exactly matches your deployed callback URL, for example:
https://yourdomain.com/api/auth/callback/googlehttps://your-app.vercel.app/api/auth/callback/google
It must match exactly:
httpvshttps- domain
- path
- trailing slash
- subdomain
2) Check your app’s redirect_uri / callback route
Make sure your app is generating the production callback URL correctly. If you’re using:
- NextAuth / Auth.js: confirm
NEXTAUTH_URLorAUTH_URL - Passport / custom OAuth: confirm the callback URL passed to Google is the production one
3) Set production env vars
Common issue: local env vars still point to localhost.
Examples:
GOOGLE_CLIENT_IDGOOGLE_CLIENT_SECRETNEXTAUTH_URL=https://yourdomain.comNEXTAUTH_SECRET=...
If using Auth.js v5, also check:
AUTH_URLAUTH_TRUST_HOST=true(sometimes needed behind proxies/platforms)
4) Make sure your deploy platform forwards HTTPS correctly
If you’re behind a proxy/load balancer, your app may think it’s on http:// and generate the wrong callback URL.
5) Check Google Cloud Console “Authorized JavaScript origins”
If your flow needs it, add:
https://yourdomain.com
6) Inspect the exact error
Common Google errors:
redirect_uri_mismatch→ callback URL mismatchunauthorized_client→ wrong client type or configorigin_mismatch→ missing JS originaccess_denied→ user denied consent or app verification issues
If you’re using NextAuth/Auth.js
Production issues are often fixed by:
NEXTAUTH_URL=https://yourdomain.com
GOOGLE_CLIENT_ID=...
GOOGLE_CLIENT_SECRET=...
And in Google Console:
https://yourdomain.com/api/auth/callback/google
If you want, send me:
- The exact error message from Google
- Your callback URL route
- Whether you’re using NextAuth/Auth.js, Passport, or custom OAuth
- Your deploy platform (Vercel, Render, AWS, etc.)
…and I can tell you the exact fix.