grpc/grpc-go · error

no alts.AuthInfo found in Peer

Error message

no alts.AuthInfo found in Peer

What it means

Returned by alts.AuthInfoFromPeer when the peer's AuthInfo field is not of the alts.AuthInfo type. The function performs a Go type assertion (p.AuthInfo.(AuthInfo)) which fails if the connection was established with non-ALTS credentials such as TLS, insecure, or xDS credentials. This means the active transport security does not use the ALTS protocol.

Solutions

  1. Verify the channel/server is actually using alts.NewClientCredentials or alts.NewServerCredentials as its TransportCredentials.
  2. Before calling ALTS-specific helpers, check the AuthType of the peer's AuthInfo and branch to the appropriate credential logic.
  3. If the deployment does not require ALTS, switch to the TLS AuthInfo equivalents (credentials.TLSInfo).

Example fix

// before
ai, err := alts.AuthInfoFromPeer(peer) // fails on TLS connections
// after
switch ai := peer.AuthInfo.(type) {
case alts.AuthInfo:
    // ALTS-specific authorization
case credentials.TLSInfo:
    // TLS-specific authorization
default:
    return status.Error(codes.Unauthenticated, "unsupported credentials")
}
Defensive patterns

Strategy: type-guard

Validate before calling

// Check AuthInfo type before calling ALTS-specific helpers:
func isALTSAuthInfo(p *peer.Peer) bool {
    _, ok := p.AuthInfo.(alts.AuthInfo)
    return ok
}

Type guard

func isALTSAuthInfo(p *peer.Peer) bool {
    _, ok := p.AuthInfo.(alts.AuthInfo)
    return ok
}

Try / catch

ai, err := alts.AuthInfoFromPeer(p)
if err != nil {
    // connection is not ALTS; handle TLS or insecure accordingly
    return status.Error(codes.Unauthenticated, "ALTS credentials required")
}

Prevention

When it happens

Trigger: Calling alts.AuthInfoFromPeer on a peer obtained from a connection that uses credentials.NewTLS, insecure.NewCredentials, or any non-ALTS TransportCredentials. Also triggered when ClientAuthorizationCheck is invoked on a context whose connection was not negotiated with ALTS.

Common situations: A server configured with mixed or fallback credentials (e.g., xDS with TLS fallback) receives a connection that did not negotiate ALTS. Developers assume all connections use ALTS but the channel was created with TLS or insecure credentials. Common during migrations from ALTS to TLS or when testing locally without the ALTS handshake server.

Related errors


AI-assisted analysis of grpc/grpc-go@0c51461d27 (2026-08-11). Data as JSON: /api/errors/63d7a117e2b9212f. Report an issue: GitHub.

Appendix: source

Thrown at credentials/alts/utils.go:49

// AuthInfoFromContext extracts the alts.AuthInfo object from the given context,
// if it exists. This API should be used by gRPC server RPC handlers to get
// information about the communicating peer. For client-side, use grpc.Peer()
// CallOption.
func AuthInfoFromContext(ctx context.Context) (AuthInfo, error) {
	p, ok := peer.FromContext(ctx)
	if !ok {
		return nil, errors.New("no Peer found in Context")
	}
	return AuthInfoFromPeer(p)
}

// AuthInfoFromPeer extracts the alts.AuthInfo object from the given peer, if it
// exists. This API should be used by gRPC clients after obtaining a peer object
// using the grpc.Peer() CallOption.
func AuthInfoFromPeer(p *peer.Peer) (AuthInfo, error) {
	altsAuthInfo, ok := p.AuthInfo.(AuthInfo)
	if !ok {
		return nil, errors.New("no alts.AuthInfo found in Peer")
	}
	return altsAuthInfo, nil
}

// ClientAuthorizationCheck checks whether the client is authorized to access
// the requested resources based on the given expected client service accounts.
// This API should be used by gRPC server RPC handlers. This API should not be
// used by clients.
func ClientAuthorizationCheck(ctx context.Context, expectedServiceAccounts []string) error {
	authInfo, err := AuthInfoFromContext(ctx)
	if err != nil {
		return status.Errorf(codes.PermissionDenied, "The context is not an ALTS-compatible context: %v", err)
	}
	peer := authInfo.PeerServiceAccount()
	for _, sa := range expectedServiceAccounts {
		if strings.EqualFold(peer, sa) {
			return nil
		}

View on GitHub (pinned to 0c51461d27)