Repository navigation
[Bug]: T3 Connect environment is discoverable but relay connection is unauthorized (endpoint_provider_not_managed) #6568
Description
Activity
- addedbugSomething is broken or behaving incorrectly.Something is broken or behaving incorrectly.needs-triageIssue needs maintainer review and initial categorization.Issue needs maintainer review and initial categorization.
on Aug 14, 2026 I am having a similar issue with t3 connect right now, I run a remote/server instance and connect via mobile & desktop to it, randomly lost connection and was getting an
environment_link_not_founderror so I stopped my server, logged out the tunnel, logged it back in, and then it started giving meendpoint_provider_not_managedafter starting t3code back up.Hit the same
endpoint_provider_not_managedon Windows desktop 0.0.40 + iOS and traced it through the code. Root cause and a working recovery below, in case it helps here.What the error means
The relay refuses
connectwhenever its stored link for the environment hasendpoint.providerKind !== "cloudflare_tunnel"(infra/relay/src/environments/EnvironmentConnector.ts,resolveManagedEndpoint). The only other kind the desktop sends ismanual, which is the "publish only" link. Your screenshot showing the environment as "Activity publishing only" under Account > T3 Connect is that exact state: the relay thinks there is no managed tunnel, so it will not route a connection to it, while the environment stays discoverable and health checks keep passing.How it gets there
The desktop Settings > Connections toggles: with Publish agent activity on, turning T3 Connect off does not unlink. It relinks in publish-only mode (
useCloudLinkController.ts,mode: desired.managedTunnel ? "managed" : "publish_only"). And the relink flow commits the relay record before it persists the local relay config (applyCloudRelayConfiginapps/server/src/cloud/http.tswrites six secrets one at a time with no rollback). In my case the local write failed after the first file, so the relay hadmanualwhile the desktop still believed it was managed and cloudflared kept the old tunnel up. Turning the toggle on again then does nothing, because the UI only relinks when its localmanagedTunnelActivediffers from the desired state. Filed as #11898 (server, non-atomic apply) and #11899 (UI cannot detect or repair the drift).Recovery that worked
Settings > Connections: turn Publish agent activity off, then T3 Connect off (only that combination actually unlinks), then T3 Connect on, then publishing back on. That rewrote the relay record as
cloudflare_tunneland the phone connected on the next try.@hichenym your "already linked to a different cloud account" error is an extra layer on top of this: that check is
validateLinkedCloudUsercomparing the relay'scloudUserIdagainst~/.t3/userdata/secrets/cloud-linked-user-id.binon the desktop. If those differ, the toggle sequence above will fail at the "on" step. Deleting that one file (with T3 Code closed) and then running the sequence should let the current account take the link. @Destreyf the tunnel logout/login path lands in the same relay state, so the same sequence should apply.@ElliotDrel mine resolved itself at some point, not sure when, but t3 connect works for me now without any changes on my end aside from removing my workaround SSH connections, I am on nightly though.
Settings > Connections: turn Publish agent activity off, then T3 Connect off (only that combination actually unlinks), then T3 Connect on, then publishing back on. That rewrote the relay record as cloudflare_tunnel and the phone connected on the next try.
worked for me on stable too.
Reacted by Lubomír Blažek
Before submitting
Area
apps/web
Steps to reproduce
Summary
My Windows T3 Code environment is visible in the Android T3 Code app through T3 Connect, but it cannot be connected to.
The Android client reports that the relay connection is unauthorized because the endpoint provider is not managed. At the same time, the Windows desktop app cannot update or disable T3 Connect because it says that the environment is already linked to a different cloud account.
The environment is therefore stuck in an inconsistent state:
Environment
DESKTOP-PCKC6UC<paste exact version><paste exact version><winget / GitHub release / other>Android error
The Android app lists the environment under T3 Connect, but it remains offline and displays:
Screenshots, recordings, or supporting files
No response
Workaround
No response