scribase
SQLSTATE 28P01invalid_passwordHTTP 403

Postgres error 28P01: invalid password

password authentication failed for user "x"

The server rejected the password for that role.

Common causes

  • A wrong or rotated password in the connection string.
  • Special characters in the password not URL-encoded in a postgresql:// URL (@, :, /, # and %).
  • Using the password of a different project or branch, or the wrong user name format a pooler expects.

How to fix it

  • Copy the connection string again from the dashboard.
  • URL-encode the password, for example with encodeURIComponent.
  • Rotate the password and update every place that uses it.

Through a REST API

PostgREST, the REST layer behind supabase-js and Scribase, answers HTTP 403 for this error and returns the SQLSTATE in the code field of the JSON error body.

Questions

What does Postgres error 28P01 mean?

28P01 is invalid_password in class 28 (Invalid Authorization Specification). The server rejected the password for that role.

How do I fix 28P01?

Copy the connection string again from the dashboard. URL-encode the password, for example with encodeURIComponent. Rotate the password and update every place that uses it.

What HTTP status does a REST API return for 28P01?

PostgREST, the REST layer behind supabase-js, answers 403.

Other class 28 errors

  • 28000 no pg_hba.conf entry for host / role "x" is not permitted to log in