jackc/pgx · error

unexpected message type during OAuth auth: %T

Error message

unexpected message type during OAuth auth: %T

What it means

The OAuth SASL exchange received a backend message that is neither AuthenticationSASLContinue nor ErrorResponse. This indicates a protocol desynchronization or a non-conforming server/proxy during the OAuth handshake; the message is aborted since no further progress is possible.

Solutions

  1. Inspect the %T value in the error to identify which message broke the exchange
  2. Verify you are connecting to a PostgreSQL server (or proxy) that supports OAuth per RFC 7628
  3. Enable tracing to capture the full message stream leading up to the failure
  4. Test against the server directly with psql to confirm OAuth support
Defensive patterns

Strategy: type-guard

When it happens

Trigger: Thrown at pgconn/auth_oauth.go:65 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/8c7944715991dff7. Report an issue: GitHub.

Appendix: source

Thrown at pgconn/auth_oauth.go:65

		errResponse := struct {
			Status              string `json:"status"`
			Scope               string `json:"scope"`
			OpenIDConfiguration string `json:"openid-configuration"`
		}{}
		err := json.Unmarshal(m.Data, &errResponse)
		if err != nil {
			return fmt.Errorf("invalid OAuth error response from server: %w", err)
		}

		// Per RFC 7628 section 3.2.3, we should send a SASLResponse which only contains \x01.
		// However, since the connection will be closed anyway, we can skip this
		return fmt.Errorf("OAuth authentication failed: %s", errResponse.Status)

	case *pgproto3.ErrorResponse:
		return ErrorResponseToPgError(m)

	default:
		return fmt.Errorf("unexpected message type during OAuth auth: %T", msg)
	}
}

View on GitHub (pinned to ec1a0befd2)