Supabase incident
401 errors due to JWT rejections
Started
August 14, 2026 at 02:23 AM UTC
Duration
46d 16h
Resolved
September 29, 2026 at 06:46 PM UTC
Updates timeline
- Identified
We have identified the root cause of newly refreshed JWTs being rejected by the API, resulting in HTTP 401 errors for affected sessions. We are working on a fix and will provide updates as things progress.
- Identified
Our teams are continuing to work on the fix and rollout is underway for selected customers. We will provide another update as we are applying the fix to all impacted users.
- Identified
Fixes for this issue are being sequentially rolled out. The impact of the issue is limited to a subset of new projects that can experience it upon some JWT renewals. We will update the status when all the fix rollouts have completed.
- Identified
As part of the incident remediation flow, we have separately identified "/lib/aarch64-linux-gnu/libc.so.6: version `GLIBC_2.34' not found" error between 11:15 - 16:24 UTC today affecting PostgREST. This has been fixed and we can see the error rates have subsided.
- Identified
We are continuing to test and rollout the fixes for intermittent HTTP 401 errors. In most cases, waiting and refreshing is successful. We will monitor eu-central-2 over the weekend and are preparing for the fix to be pushed to all regions starting Monday. Thank you for your patience while we've worked on multiple fixes for this issue.
- Identified
We are continuing to rollout the fixes for intermittent HTTP 401 errors. In most cases, waiting and refreshing is successful. This fix has been applied to the following regions: ap-east-1 ap-northeast-1 ap-northeast-2 ap-south-1 ap-southeast-1 ap-southeast-2 ca-central-1 eu-central-1 eu-central-2 eu-north-1 eu-west-2 eu-west-3 We will continue rolling out this fix to the remaining regions throughout this week and provide updates as more regions are successful.
- Identified
PostgREST 14.17 has now been rolled out to all regions. Some customers have reported that restarting their project after the rollout resolved this issue. To restart your project, go to the General settings page in the dashboard and select Restart project. Please contact our support team if the issue persists after a restart.
- Identified
We continue to monitor the fixes introduced by this latest rollout. If you are continuing to see these errors, some customers have reported that restarting their project after the rollout resolved this issue. To restart your project, go to the General settings page in the dashboard and select Restart project. Please contact our support team if the issue persists after a restart.
- Identified
We have seen reports that the JWT rejection issue persisted with 14.17, and due to <a href="https://status.supabase.com/incidents/bv4ntm4x0btf">some unintended performance side effects</a>, we have rolled back to Postgrest 14.5. The team continues to investigate the JWT issue and hopes to have a solution soon.
- Identified
A stale time cache has been identified as the cause of this issue. A targeted fix has been written and is undergoing internal testing. It will be rolled out when testing is complete. Thank you for your patience while we investigated this issue. We will update the status page when the fix is rolled out.
- Identified
Testing results have been positive. Following some additional checks today, we plan to expand the rollout. We’ll continue to monitor progress and provide further updates as they become available.
- Identified
We continue to monitor progress and are slowly updating each region. Thank you for your patience on this issue.
- Identified
To resolve this issue, our fleet requires a change to our deploy process. We have spent this week making these changes and will be implementing them throughout this weekend, starting on Friday, September 18. Once this change is implemented, we will release a new Supabase version that impacted users can upgrade to from their dashboard. Completing that upgrade will resolve this issue. We recognize that this is added work for our customers. This issue has been open for over a month, as we tried to make this change on each project's behalf. In an effort to resolve this sooner, we have opted to make this deployment process change and ask users to upgrade.
- Identified
We have rolled out the deployment process changes to eu-central-2 and continue to monitor. We will provide additional updates as we make this change to other regions. Once this change is implemented across all regions, we will release a new Supabase version that impacted users can upgrade to from their dashboard. Completing that upgrade will resolve this issue.
- Identified
The deployment process changes have been rolled out across all regions. We will monitor throughout the weekend. The new Supabase version will be released early next week. Once it is released, impacted users can upgrade to from their dashboard to resolve this issue. Thank you again for your patience while we worked through this. We will provide an update once the new version is available and users can upgrade.
- Resolved
The latest Supabase version has been released. All users impacted by this issue can now upgrade from the dashboard to resolve this issue. Since this new version is released, we will resolve this issue. If you have any questions about upgrading, please refer to our documentation for more information: https://supabase.com/docs/guides/platform/upgrading Thank you again for your patience while we worked on resolving this issue.
Get an email the next time Supabase goes down
Outage alerts for Supabase, straight to your inbox. No account needed, unsubscribe in every email.
Watching more than one service? A free account covers 5 services + a daily digest — and Pro is currently free.
Live Supabase status
Current indicator + 24h latency
All incidents
Cross-service timeline
Subscribe via RSS
Atom feed for any reader