Repository navigation
[Bug]: T3 Connect: The environment credential is invalid. #5332
Description
Activity
- addedbugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.needs-triageIssue needs maintainer review and initial categorization.Issue needs maintainer review and initial categorization.
on Aug 4, 2026 I am also facing the same error. For me I am not using t3 connect instead I am getting this error when using
t3 serve. The generated code works correctly for the first device. Any attempt to add the same remote environment on any other device results in this error.kylescudder commented
on Aug 8, 2026 More actionsUpdate: I resolved my reproduction. This was not caused by a corrupt persisted environment credential.
After adding credential-safe diagnostics around DPoP verification, the server reported the actual rejection reason:
DPoP proof verification failed reason: DPoP proof is outside the allowed time window. requestProtocol: https: requestHost: prod-aa75a8b4828aa058.t3coderelay.com requestPath: /oauth/token forwardedProtocol: https cloudflareVisitor: {"scheme":"https"}The VPS clock was not synchronized:
System clock synchronized: no NTP service: active Packet count: 0NTP requests were timing out because UDP response traffic was blocked by the provider firewall. Once I allowed incoming UDP traffic from source port 123 and restarted
systemd-timesyncd, it synchronized and corrected approximately 11 seconds of clock drift:System clock synchronized: yes Offset: +10.959798s Packet count: 1The existing T3 Connect environment then connected successfully from the mobile app without relinking or regenerating its credential.
There was a separate network issue where Cloudflare Tunnel could not establish QUIC because UDP was blocked. Running the tunnel over HTTP/2 with
TUNNEL_TRANSPORT_PROTOCOL=http2handled that; it was not the cause of theinvalid_credentialresponse.So, for my reproduction:
- The environment credential was valid.
- The public HTTPS request URL was reconstructed correctly.
- The
401 invalid_credentialresponse was caused by clock skew during DPoP verification. - Restoring working NTP synchronization fixed the connection.
Other reports on this issue may still have different causes, but regenerating the environment credential was not required in my case.
I just ran into the same issue. In my case, the Windows environment host’s clock was about 11 seconds behind.
After diagnosing it with T3 (ha!), clicking Sync now under Windows Settings → Time & language → Date & time fixed the connection immediately. I did not need to relink the environment or regenerate its credentials.
This matches the clock-skew diagnosis above. I’d suggest that when authentication fails specifically because the DPoP proof falls outside the permitted time window, the app show a more actionable message:
The environment host’s clock appears out of sync. Sync its date and time, then retry.
Other invalid-credential failures can remain generic.
Reacted by Kyle Scudder, Brian Bowman and gabew100One thing I noticed, is that if you try add the 4th device in the tunnel, you also get this error message instead of something reporting you ran out of devices, subscribe and whatever.


Before submitting
Area
apps/desktop
Steps to reproduce
Trying to connect to another remote environment
Expected behavior
T3 would connect and have access to such environment
Actual behavior
I have 3 machines in my network, all of them connect to T3 Connect and all of them can connect to each other, except my Macbook can't connect to the Windows instance. The error is:
The environment credential is invalid.Impact
Blocks work completely
Version or commit
0.0.32
Environment
27.0 Beta (26A5388g), Windows 11
Logs or stack traces
Screenshots, recordings, or supporting files
image.png
image.png
Workaround
No response