jackc/pgx · error
unexpected message type during OAuth auth: %T
Error message
unexpected message type during OAuth auth: %T
What it means
The OAuth SASL exchange received a backend message that is neither AuthenticationSASLContinue nor ErrorResponse. This indicates a protocol desynchronization or a non-conforming server/proxy during the OAuth handshake; the message is aborted since no further progress is possible.
Solutions
- Inspect the %T value in the error to identify which message broke the exchange
- Verify you are connecting to a PostgreSQL server (or proxy) that supports OAuth per RFC 7628
- Enable tracing to capture the full message stream leading up to the failure
- Test against the server directly with psql to confirm OAuth support
Defensive patterns
Strategy: type-guard
When it happens
Trigger: Thrown at pgconn/auth_oauth.go:65 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04).
Data as JSON: /api/errors/8c7944715991dff7.
Report an issue: GitHub.
Appendix: source
Thrown at pgconn/auth_oauth.go:65
errResponse := struct {
Status string `json:"status"`
Scope string `json:"scope"`
OpenIDConfiguration string `json:"openid-configuration"`
}{}
err := json.Unmarshal(m.Data, &errResponse)
if err != nil {
return fmt.Errorf("invalid OAuth error response from server: %w", err)
}
// Per RFC 7628 section 3.2.3, we should send a SASLResponse which only contains \x01.
// However, since the connection will be closed anyway, we can skip this
return fmt.Errorf("OAuth authentication failed: %s", errResponse.Status)
case *pgproto3.ErrorResponse:
return ErrorResponseToPgError(m)
default:
return fmt.Errorf("unexpected message type during OAuth auth: %T", msg)
}
}
View on GitHub (pinned to ec1a0befd2)