401 errors due to JWT rejections

Incident Report for Supabase

Update

Testing results have been positive.
Following some additional checks today, we plan to expand the rollout.
We’ll continue to monitor progress and provide further updates as they become available.
Posted Sep 07, 2026 - 09:49 UTC

Update

A stale time cache has been identified as the cause of this issue. A targeted fix has been written and is undergoing internal testing. It will be rolled out when testing is complete. Thank you for your patience while we investigated this issue. We will update the status page when the fix is rolled out.
Posted Sep 02, 2026 - 19:38 UTC

Update

We have seen reports that the JWT rejection issue persisted with 14.17, and due to some unintended performance side effects, we have rolled back to Postgrest 14.5. The team continues to investigate the JWT issue and hopes to have a solution soon.
Posted Aug 31, 2026 - 19:52 UTC

Update

We continue to monitor the fixes introduced by this latest rollout. If you are continuing to see these errors, some customers have reported that restarting their project after the rollout resolved this issue.

To restart your project, go to the General settings page in the dashboard and select Restart project.

Please contact our support team if the issue persists after a restart.
Posted Aug 28, 2026 - 23:44 UTC

Update

PostgREST 14.17 has now been rolled out to all regions.
Some customers have reported that restarting their project after the rollout resolved this issue.
To restart your project, go to the General settings page in the dashboard and select Restart project.
Please contact our support team if the issue persists after a restart.
Posted Aug 27, 2026 - 17:17 UTC

Update

We are continuing to rollout the fixes for intermittent HTTP 401 errors. In most cases, waiting and refreshing is successful.

This fix has been applied to the following regions:
ap-east-1
ap-northeast-1
ap-northeast-2
ap-south-1
ap-southeast-1
ap-southeast-2
ca-central-1
eu-central-1
eu-central-2
eu-north-1
eu-west-2
eu-west-3

We will continue rolling out this fix to the remaining regions throughout this week and provide updates as more regions are successful.
Posted Aug 25, 2026 - 18:41 UTC

Update

We are continuing to test and rollout the fixes for intermittent HTTP 401 errors. In most cases, waiting and refreshing is successful.

We will monitor eu-central-2 over the weekend and are preparing for the fix to be pushed to all regions starting Monday. Thank you for your patience while we've worked on multiple fixes for this issue.
Posted Aug 21, 2026 - 17:21 UTC

Update

As part of the incident remediation flow, we have separately identified "/lib/aarch64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found" error between 11:15 - 16:24 UTC today affecting PostgREST. This has been fixed and we can see the error rates have subsided.
Posted Aug 20, 2026 - 16:37 UTC

Update

Fixes for this issue are being sequentially rolled out. The impact of the issue is limited to a subset of new projects that can experience it upon some JWT renewals. We will update the status when all the fix rollouts have completed.
Posted Aug 18, 2026 - 18:38 UTC

Update

Our teams are continuing to work on the fix and rollout is underway for selected customers. We will provide another update as we are applying the fix to all impacted users.
Posted Aug 14, 2026 - 07:53 UTC

Identified

We have identified the root cause of newly refreshed JWTs being rejected by the API, resulting in HTTP 401 errors for affected sessions. We are working on a fix and will provide updates as things progress.
Posted Aug 14, 2026 - 02:23 UTC
This incident affects: API Gateway.