Summary
icp identity link web opens Internet Identity /cli with a full
#public_key=…&callback=…&nonce=…&domain=… fragment, but the authorize UI never appears:
- With the hash: blank white page.
- Without the hash (
https://id.ai/cli): “Invalid request” —
“It seems like an invalid CLI authentication request was received. You can close this window.”
(screenshot attached)
Reproduced on a daily-driver Ubuntu machine and a fresh Ubuntu desktop VM.
Same failure in Google Chrome, Chromium, and Firefox.
Same for --app https://oisy.com and --app https://demo.gos.earth.
Same for --auth https://id.ai and --auth https://identity.ic0.app (same canister).
Not a duplicate of #4171 (that flow reaches Allow access, then Unauthorized after a
renamed default account). We never get a sign-in / Allow screen.
Steps to reproduce
export PATH="$HOME/.cargo/bin:$PATH"
icp identity link web oisy_probe --app https://oisy.com --storage plaintext
Press Enter. CLI prints ✓ Browser opened and waits on “Linking web-based identity”.
Example URL (shape):
https://identity.ic0.app/cli#public_key=MCowBQYDK2VwAyEA…&callback=http%3A%2F%2F127.0.0.1%3A38119%2F&nonce=…&domain=https%3A%2F%2Foisy.com
Expected
/cli shows the CLI authorize UI, then POSTs the delegation to http://127.0.0.1:<port>/.
Actual
Blank /cli with fragment present. Bare /cli shows Invalid request (screenshot).
icp never completes.
Environment (host that first hit this)
| Piece |
Version |
| OS |
Ubuntu 22.04.5 LTS |
| Kernel |
Linux 6.8.0-138-generic x86_64 |
| Session |
GNOME (ubuntu:GNOME), Wayland (XDG_SESSION_TYPE=wayland, WAYLAND_DISPLAY=wayland-0, DISPLAY=:0) |
| icp-cli |
1.3.0 (icp --version), binary ~/.cargo/bin/icp (official-style ELF installer, 2026-08-07) |
npm @icp-sdk/icp-cli |
0.3.0 also present under ~/.npm-global — not on PATH for this test (which icp = cargo binary) |
| Node / npm |
v22.16.0 / 10.9.2 (only relevant if someone uses the npm wrapper; we invoked the cargo icp) |
| Google Chrome |
150.0.7871.186 — failed |
| Chromium |
151.0.7922.108 (snap latest/stable) — failed |
| Firefox |
154.0.1 (snap 154.0.1-1, latest/stable) — failed |
| xdg-open |
1.1.3 (BROWSER unset) |
| libssl3 |
3.0.2-0ubuntu1.29 |
| libdbus-1-3 |
1.12.20-2ubuntu4.1 |
| ca-certificates |
20260601~22.04.1 |
VM: fresh Ubuntu desktop, icp-cli via icp-cli-installer.sh, Firefox (and/or Chromium) — same blank / Invalid request.
Related
Summary
icp identity link webopens Internet Identity/cliwith a full#public_key=…&callback=…&nonce=…&domain=…fragment, but the authorize UI never appears:https://id.ai/cli): “Invalid request” —“It seems like an invalid CLI authentication request was received. You can close this window.”
(screenshot attached)
Reproduced on a daily-driver Ubuntu machine and a fresh Ubuntu desktop VM.
Same failure in Google Chrome, Chromium, and Firefox.
Same for
--app https://oisy.comand--app https://demo.gos.earth.Same for
--auth https://id.aiand--auth https://identity.ic0.app(same canister).Not a duplicate of #4171 (that flow reaches Allow access, then Unauthorized after a
renamed default account). We never get a sign-in / Allow screen.
Steps to reproduce
Press Enter. CLI prints
✓ Browser openedand waits on “Linking web-based identity”.Example URL (shape):
https://identity.ic0.app/cli#public_key=MCowBQYDK2VwAyEA…&callback=http%3A%2F%2F127.0.0.1%3A38119%2F&nonce=…&domain=https%3A%2F%2Foisy.comExpected
/clishows the CLI authorize UI, then POSTs the delegation tohttp://127.0.0.1:<port>/.Actual
Blank
/cliwith fragment present. Bare/clishows Invalid request (screenshot).icpnever completes.Environment (host that first hit this)
ubuntu:GNOME), Wayland (XDG_SESSION_TYPE=wayland,WAYLAND_DISPLAY=wayland-0,DISPLAY=:0)icp --version), binary~/.cargo/bin/icp(official-style ELF installer, 2026-08-07)@icp-sdk/icp-cli~/.npm-global— not onPATHfor this test (which icp= cargo binary)icp)latest/stable) — failed154.0.1-1,latest/stable) — failedBROWSERunset)VM: fresh Ubuntu desktop, icp-cli via
icp-cli-installer.sh, Firefox (and/or Chromium) — same blank / Invalid request.Related
identity link web --app <domain>returns Unauthorized once the default account for that origin has been renamed #4171