{"record":{"id":"9ef588fbe22807da","repo":"apache/seatunnel","slug":"edge-socket-authentication-rejected-auth-failed","errorCode":null,"errorMessage":"Edge socket authentication rejected (AUTH_FAILED): check output token matches EdgeSocket source secret_key","messagePattern":"Edge socket authentication rejected \\(AUTH_FAILED\\): check output token matches EdgeSocket source secret_key","errorType":"exception","errorClass":"EdgeSocketCollectorRejectedException","httpStatus":null,"severity":"critical","filePath":"seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java","lineNumber":96,"sourceCode":"                            + \", \"\n                            + EdgeSocketProtocol.RESP_RETRY\n                            + \", or \"\n                            + EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX\n                            + \"<ms>)\");\n        }\n        throw new IOException(\n                \"Exceeded maxBatchSendAttempts=\"\n                        + config.getMaxBatchSendAttempts()\n                        + \" without RECEIVED for batch \"\n                        + batchId);\n    }\n\n    private static void handleAuthResponse(String reply) throws IOException {\n        if (EdgeSocketProtocol.RESP_REJECTED.equals(reply)) {\n            throw new EdgeSocketCollectorRejectedException();\n        }\n        if (EdgeSocketProtocol.RESP_AUTH_FAILED.equals(reply)) {\n            throw new EdgeSocketCollectorRejectedException(\n                    \"Edge socket authentication rejected (AUTH_FAILED): check output token matches\"\n                            + \" EdgeSocket source secret_key\");\n        }\n        if (!EdgeSocketProtocol.RESP_ACK.equals(reply)) {\n            throw new IOException(\n                    \"Unexpected auth response: \"\n                            + reply\n                            + \" (expected \"\n                            + EdgeSocketProtocol.RESP_ACK\n                            + \" or \"\n                            + EdgeSocketProtocol.RESP_REJECTED\n                            + \")\");\n        }\n    }\n\n    private static long parseQueueFullBackoffMs(String reply) {\n        String suffix = reply.substring(EdgeSocketProtocol.RESP_QUEUE_FULL_PREFIX.length());\n        try {","sourceCodeStart":78,"sourceCodeEnd":114,"githubUrl":"https://github.com/apache/seatunnel/blob/cf67b549a7a6c35fa0beb12d83c62892427ea919/seatunnel-edge-agent/seatunnel-edge-agent-transport/src/main/java/org/apache/seatunnel/edge/agent/transport/socket/EdgeSocketLineTransport.java#L78-L114","documentation":"During the AUTH handshake, handleAuthResponse maps the collector's reply to outcomes: REJECTED means the collector refused this agent, AUTH_FAILED means the presented token did not authenticate. This EdgeSocketCollectorRejectedException with the AUTH_FAILED message signals the client's auth token does not match the EdgeSocket source's secret_key.","triggerScenarios":"authenticate() writes the AUTH line with config.getToken(); the collector answers AUTH_FAILED because the token differs from its configured secret_key.","commonSituations":"output token option on the agent sink and secret_key on the EdgeSocket source configured with different values; token rotated on the server only; copy/paste truncation of the token; trailing whitespace or quoting issues in the config file.","solutions":["Set the agent's output token to exactly the EdgeSocket source's secret_key value","Redeploy/restart both jobs after any token rotation so both sides agree","Verify the token has no truncated characters, surrounding quotes, or whitespace in the config","Check that the collector is reading the config file you think it is (right cluster/namespace)"],"exampleFix":"# before (agent sink)\ntoken = \"tok-old-value\"\n# source\nsecret_key = \"tok-current-value\"\n# after\ntoken = \"tok-current-value\"\nsecret_key = \"tok-current-value\"","handlingStrategy":"validation","validationCode":"if (!Objects.equals(agentToken, collectorSecretKey)) { throw new IllegalStateException(\"agent token must equal EdgeSocket source secret_key\"); }","typeGuard":null,"tryCatchPattern":"try { client.probeReachable(); } catch (EdgeSocketCollectorRejectedException e) { alertOperator(\"AUTH_FAILED: sync output token with source secret_key\"); throw e; }","preventionTips":["Deploy token and secret_key from one shared secret source","Rotate tokens on both sides in the same change window","Validate tokens with a lightweight auth probe before production sends","Watch for config quoting/whitespace corrupting token values"],"tags":["authentication","token","config-mismatch","socket"],"backgroundTag":"authentication-required","analyzedSha":"cf67b549a7a6c35fa0beb12d83c62892427ea919","analyzedAt":"2026-09-10T21:44:55.265Z","contentChangedAt":"2026-09-10T21:44:55.265Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}