scribase
SQLSTATE 28000invalid_authorization_specificationHTTP 403

Postgres error 28000: invalid authorization specification

no pg_hba.conf entry for host / role "x" is not permitted to log in

The server does not allow this role to connect from this address or with this method.

Common causes

  • Connecting without TLS to a server that requires it.
  • The client IP is not in the allowed ranges.
  • The role has NOLOGIN, such as an API role used only through a gateway.

How to fix it

  • Add sslmode=require to the connection string.
  • Connect from an allowed network or update the allow list.
  • Use a login role; do not connect directly as roles meant for the API.

Through a REST API

PostgREST, the REST layer behind supabase-js and Scribase, answers HTTP 403 for this error and returns the SQLSTATE in the code field of the JSON error body.

Questions

What does Postgres error 28000 mean?

28000 is invalid_authorization_specification in class 28 (Invalid Authorization Specification). The server does not allow this role to connect from this address or with this method.

How do I fix 28000?

Add sslmode=require to the connection string. Connect from an allowed network or update the allow list. Use a login role; do not connect directly as roles meant for the API.

What HTTP status does a REST API return for 28000?

PostgREST, the REST layer behind supabase-js, answers 403.

Other class 28 errors

  • 28P01 password authentication failed for user "x"