jackc/pgx · error

expected AuthenticationSASLContinue message but received…

Error message

expected AuthenticationSASLContinue message but received unexpected message %T

What it means

During SCRAM authentication the client expected an AuthenticationSASLContinue message (the server-first-message) but received a different backend message type. This means the server deviated from the SASL exchange sequence; authentication cannot continue.

Solutions

  1. Check the %T in the error to see what message arrived instead
  2. Verify the server supports SCRAM-SHA-256 authentication
  3. Ensure no middleware/proxy is mangling the protocol stream
  4. Capture a trace of the authentication exchange for diagnosis
Defensive patterns

Strategy: type-guard

When it happens

Trigger: Thrown at pgconn/auth_scram.go:126 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/2ae36a1aba91cbe0. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/auth_scram.go:126

	if err != nil {
		return err
	}
	return sc.recvServerFinalMessage(saslFinal.Data)
}

func (c *PgConn) rxSASLContinue() (*pgproto3.AuthenticationSASLContinue, error) {
	msg, err := c.receiveMessage()
	if err != nil {
		return nil, err
	}
	switch m := msg.(type) {
	case *pgproto3.AuthenticationSASLContinue:
		return m, nil
	case *pgproto3.ErrorResponse:
		return nil, ErrorResponseToPgError(m)
	}

	return nil, fmt.Errorf("expected AuthenticationSASLContinue message but received unexpected message %T", msg)
}

func (c *PgConn) rxSASLFinal() (*pgproto3.AuthenticationSASLFinal, error) {
	msg, err := c.receiveMessage()
	if err != nil {
		return nil, err
	}
	switch m := msg.(type) {
	case *pgproto3.AuthenticationSASLFinal:
		return m, nil
	case *pgproto3.ErrorResponse:
		return nil, ErrorResponseToPgError(m)
	}

	return nil, fmt.Errorf("expected AuthenticationSASLFinal message but received unexpected message %T", msg)
}

type scramClient struct {

View on GitHub (pinned to ec1a0befd2)