brianc/node-postgres · error · Error
SASL: SCRAM-SERVER-FIRST-MESSAGE: nonce missing
Error message
SASL: SCRAM-SERVER-FIRST-MESSAGE: nonce missing
What it means
Thrown by parseServerFirstMessage() when the server's first SASL message lacks the r= attribute (the combined client-server nonce). Per RFC 5802, the server's first message must include r=<client-nonce><server-nonce>. A missing nonce makes the SCRAM exchange impossible to continue.
Solutions
- Verify the target is a standard PostgreSQL server supporting SCRAM-SHA-256 (PostgreSQL 10+).
- Eliminate proxies or middleboxes that might truncate or alter the SASL message.
- Test the same connection with psql to isolate whether the issue is server-side or client-side.
- Update node-postgres to the latest version.
Defensive patterns
Strategy: try-catch
Try / catch
try {
await client.connect()
} catch (err) {
if (err.message.includes('nonce missing')) {
// Server's first SASL message is malformed — likely a non-conformant server or proxy corruption
throw new Error('SCRAM handshake failed: server sent no nonce')
}
throw err
} Prevention
- Verify the target is PostgreSQL 10+ with SCRAM-SHA-256 enabled.
- Eliminate proxies or middleboxes that might truncate the SASL message.
- Test with psql to confirm the server's SASL handshake is correct.
- Enable SSL/TLS to prevent data corruption in transit.
When it happens
Trigger: At sasl.js:195-196, attrPairs.get('r') returns a falsy value (undefined). This means the parsed attribute Map from the server's first message has no 'r' key — the server omitted the nonce entirely.
Common situations: Malformed or truncated server first message; connecting to a non-conformant PostgreSQL-compatible server; a proxy stripping or corrupting the authentication message; network data loss truncating the message before the nonce attribute.
Related errors
- SASL: Invalid attribute pair entry
- SASL: SCRAM-SERVER-FINAL-MESSAGE: server signature is…
- SASL: SCRAM-SERVER-FIRST-MESSAGE: invalid iteration count
- SASL: SCRAM-SERVER-FIRST-MESSAGE: iteration missing
- SASL: SCRAM-SERVER-FIRST-MESSAGE: nonce must only contain…
AI-assisted analysis of brianc/node-postgres@ff9d775abd (2026-08-11).
Data as JSON: /api/errors/741f24558ab59018.
Report an issue: GitHub.
Appendix: source
Thrown at packages/pg/lib/crypto/sasl.js:197
return new Map(
text.split(',').map((attrValue) => {
if (!/^.=/.test(attrValue)) {
throw new Error('SASL: Invalid attribute pair entry')
}
const name = attrValue[0]
const value = attrValue.substring(2)
return [name, value]
})
)
}
function parseServerFirstMessage(data) {
const attrPairs = parseAttributePairs(data)
const nonce = attrPairs.get('r')
if (!nonce) {
throw new Error('SASL: SCRAM-SERVER-FIRST-MESSAGE: nonce missing')
} else if (!isPrintableChars(nonce)) {
throw new Error('SASL: SCRAM-SERVER-FIRST-MESSAGE: nonce must only contain printable characters')
}
const salt = attrPairs.get('s')
if (!salt) {
throw new Error('SASL: SCRAM-SERVER-FIRST-MESSAGE: salt missing')
} else if (!isBase64(salt)) {
throw new Error('SASL: SCRAM-SERVER-FIRST-MESSAGE: salt must be base64')
}
const iterationText = attrPairs.get('i')
if (!iterationText) {
throw new Error('SASL: SCRAM-SERVER-FIRST-MESSAGE: iteration missing')
} else if (!/^[1-9][0-9]*$/.test(iterationText)) {
throw new Error('SASL: SCRAM-SERVER-FIRST-MESSAGE: invalid iteration count')
}
const iteration = parseInt(iterationText, 10)
return {View on GitHub (pinned to ff9d775abd)