jackc/pgx · error
OAuth authentication failed
Error message
OAuth authentication failed: %s
What it means
The server rejected OAuth authentication: it returned a well-formed RFC 7628 error envelope in the SASLContinue message, and its status field (e.g. 'not_supported' or 'invalid_token') is reported here.
Solutions
- Check the status value — obtain a fresh token or fix scopes per the server's error detail
- Verify the token provider and server agree on the OAuth issuer and scope configuration
- Use a different authentication method if the server does not support OAuth
Defensive patterns
Strategy: retry
When it happens
Trigger: Thrown at pgconn/auth_oauth.go:59 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/83f4cdd63008df70.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/auth_oauth.go:59
case *pgproto3.AuthenticationOk:
return nil
case *pgproto3.AuthenticationSASLContinue:
// Server sent error response in SASL continue
// https://www.rfc-editor.org/rfc/rfc7628.html#section-3.2.2
// https://www.rfc-editor.org/rfc/rfc7628.html#section-3.2.3
errResponse := struct {
Status string `json:"status"`
Scope string `json:"scope"`
OpenIDConfiguration string `json:"openid-configuration"`
}{}
err := json.Unmarshal(m.Data, &errResponse)
if err != nil {
return fmt.Errorf("invalid OAuth error response from server: %w", err)
}
// Per RFC 7628 section 3.2.3, we should send a SASLResponse which only contains \x01.
// However, since the connection will be closed anyway, we can skip this
return fmt.Errorf("OAuth authentication failed: %s", errResponse.Status)
case *pgproto3.ErrorResponse:
return ErrorResponseToPgError(m)
default:
return fmt.Errorf("unexpected message type during OAuth auth: %T", msg)
}
}
View on GitHub (pinned to ec1a0befd2)