This usually happens when the Android device is using Hexnode Kiosk Browser and the active kiosk policy allows access only to explicitly whitelisted websites. Even if the main web app URL is added, the app may still load additional login, authentication, or redirect URLs. If those URLs are not included in the whitelist, Hexnode Kiosk Browser blocks them and shows the “Forbidden” message.
To resolve this:
- Open the Hexnode portal and go to Policies.
- Select the kiosk policy associated with the Android tablet.
- Navigate to Kiosk Lockdown > Android Kiosk Lockdown > Website Kiosk Settings.
- Under Allowlist Websites, add the main web app URL.
- Also add any related login, authentication, or redirect URLs used by the web app.
- Save the policy.
- Go to Manage > Devices, select the tablet, and run Actions > Scan Device to force a policy sync.
After the updated policy reaches the device, reopen the web app in kiosk mode and check whether the login flow loads correctly.