Skip to content

[Bug]: T3 Connect: The environment credential is invalid. #5332

Description

@paulomanrique

Before submitting

  • I searched existing issues and did not find a duplicate.
  • I included enough detail to reproduce or investigate the problem.

Area

apps/desktop

Steps to reproduce

Trying to connect to another remote environment

Expected behavior

T3 would connect and have access to such environment

Actual behavior

I have 3 machines in my network, all of them connect to T3 Connect and all of them can connect to each other, except my Macbook can't connect to the Windows instance. The error is: The environment credential is invalid.

Impact

Blocks work completely

Version or commit

0.0.32

Environment

27.0 Beta (26A5388g), Windows 11

Logs or stack traces

Trace ID: 397a5a9c7c80045bcc7f3cd117837401

Screenshots, recordings, or supporting files

image.png
image.png

Workaround

No response

Activity

  1. added
    bugSomething is broken or behaving incorrectly.
    needs-triageIssue needs maintainer review and initial categorization.
    on Aug 4, 2026
  2. naman1-gupta commented on Aug 6, 2026

    @naman1-gupta

    I am also facing the same error. For me I am not using t3 connect instead I am getting this error when using t3 serve. The generated code works correctly for the first device. Any attempt to add the same remote environment on any other device results in this error.

  3. kylescudder commented on Aug 8, 2026

    @kylescudder

    Update: I resolved my reproduction. This was not caused by a corrupt persisted environment credential.

    After adding credential-safe diagnostics around DPoP verification, the server reported the actual rejection reason:

    DPoP proof verification failed
    reason: DPoP proof is outside the allowed time window.
    requestProtocol: https:
    requestHost: prod-aa75a8b4828aa058.t3coderelay.com
    requestPath: /oauth/token
    forwardedProtocol: https
    cloudflareVisitor: {"scheme":"https"}
    

    The VPS clock was not synchronized:

    System clock synchronized: no
    NTP service: active
    Packet count: 0
    

    NTP requests were timing out because UDP response traffic was blocked by the provider firewall. Once I allowed incoming UDP traffic from source port 123 and restarted systemd-timesyncd, it synchronized and corrected approximately 11 seconds of clock drift:

    System clock synchronized: yes
    Offset: +10.959798s
    Packet count: 1
    

    The existing T3 Connect environment then connected successfully from the mobile app without relinking or regenerating its credential.

    There was a separate network issue where Cloudflare Tunnel could not establish QUIC because UDP was blocked. Running the tunnel over HTTP/2 with TUNNEL_TRANSPORT_PROTOCOL=http2 handled that; it was not the cause of the invalid_credential response.

    So, for my reproduction:

    • The environment credential was valid.
    • The public HTTPS request URL was reconstructed correctly.
    • The 401 invalid_credential response was caused by clock skew during DPoP verification.
    • Restoring working NTP synchronization fixed the connection.

    Other reports on this issue may still have different causes, but regenerating the environment credential was not required in my case.

  4. borght-dev commented on Aug 12, 2026

    @borght-dev

    I just ran into the same issue. In my case, the Windows environment host’s clock was about 11 seconds behind.

    After diagnosing it with T3 (ha!), clicking Sync now under Windows Settings → Time & language → Date & time fixed the connection immediately. I did not need to relink the environment or regenerate its credentials.

    This matches the clock-skew diagnosis above. I’d suggest that when authentication fails specifically because the DPoP proof falls outside the permitted time window, the app show a more actionable message:

    The environment host’s clock appears out of sync. Sync its date and time, then retry.

    Other invalid-credential failures can remain generic.

  5. paulomanrique commented on Aug 16, 2026

    @paulomanrique
    Author

    One thing I noticed, is that if you try add the 4th device in the tunnel, you also get this error message instead of something reporting you ran out of devices, subscribe and whatever.

  6. agm-114 commented on Aug 19, 2026

    @agm-114

    I get the same error on Android mobile trying to connect to my desktop.
    Over time more and more "T3 Connect connect" connections are made.

    Image Image
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething is broken or behaving incorrectly.needs-triageIssue needs maintainer review and initial categorization.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions