jackc/pgx · error

invalid OAuth error response from server: %w

Error message

invalid OAuth error response from server: %w

What it means

Error "invalid OAuth error response from server: %w" thrown in jackc/pgx.

Source

Thrown at pgconn/auth_oauth.go:54

	if err != nil {
		return err
	}

	switch m := msg.(type) {
	case *pgproto3.AuthenticationOk:
		return nil
	case *pgproto3.AuthenticationSASLContinue:
		// Server sent error response in SASL continue
		// https://www.rfc-editor.org/rfc/rfc7628.html#section-3.2.2
		// https://www.rfc-editor.org/rfc/rfc7628.html#section-3.2.3
		errResponse := struct {
			Status              string `json:"status"`
			Scope               string `json:"scope"`
			OpenIDConfiguration string `json:"openid-configuration"`
		}{}
		err := json.Unmarshal(m.Data, &errResponse)
		if err != nil {
			return fmt.Errorf("invalid OAuth error response from server: %w", err)
		}

		// Per RFC 7628 section 3.2.3, we should send a SASLResponse which only contains \x01.
		// However, since the connection will be closed anyway, we can skip this
		return fmt.Errorf("OAuth authentication failed: %s", errResponse.Status)

	case *pgproto3.ErrorResponse:
		return ErrorResponseToPgError(m)

	default:
		return fmt.Errorf("unexpected message type during OAuth auth: %T", msg)
	}
}

View on GitHub (pinned to ec1a0befd2)

When it happens

Trigger: Thrown at pgconn/auth_oauth.go:54 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /data/errors/cfeb3ff95dc1b85d.json. Report an issue: GitHub.