jackc/pgx · error

unknown authentication type

Error message

unknown authentication type: %d

What it means

The frontend received an Authentication message whose auth type code is not in the known set. The %d is the unrecognized code. SCMCreds and SSPI are explicitly unimplemented and also fail here or with their own errors.

Solutions

  1. Verify the server is running a supported PostgreSQL version
  2. Check for proxies or poolers with non-standard auth injection
  3. Note SSPI and SCMCreds are unimplemented in pgx
  4. Report if a modern PostgreSQL version sends this code
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at pgproto3/frontend.go:453 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of jackc/pgx@ec1a0befd2 (2026-08-04). Data as JSON: /api/errors/648f808fab779354. Report an issue: GitHub.

Appendix: source

Thrown at pgproto3/frontend.go:453

		return &f.authenticationCleartextPassword, nil
	case AuthTypeMD5Password:
		return &f.authenticationMD5Password, nil
	case AuthTypeSCMCreds:
		return nil, errors.New("AuthTypeSCMCreds is unimplemented")
	case AuthTypeGSS:
		return &f.authenticationGSS, nil
	case AuthTypeGSSCont:
		return &f.authenticationGSSContinue, nil
	case AuthTypeSSPI:
		return nil, errors.New("AuthTypeSSPI is unimplemented")
	case AuthTypeSASL:
		return &f.authenticationSASL, nil
	case AuthTypeSASLContinue:
		return &f.authenticationSASLContinue, nil
	case AuthTypeSASLFinal:
		return &f.authenticationSASLFinal, nil
	default:
		return nil, fmt.Errorf("unknown authentication type: %d", f.authType)
	}
}

// GetAuthType returns the authType used in the current state of the frontend.
// See SetAuthType for more information.
func (f *Frontend) GetAuthType() uint32 {
	return f.authType
}

func (f *Frontend) ReadBufferLen() int {
	return f.cr.wp - f.cr.rp
}

// SetMaxBodyLen sets the maximum length of a message body in octets.
// If a message body exceeds this length, Receive will return an error.
// This is useful for protecting against a corrupted server that sends
// messages with incorrect length, which can cause memory exhaustion.
// The default value is 0.

View on GitHub (pinned to ec1a0befd2)