Skip to content

Phase vault provider: testConnection fails with "401: Token expired or deleted" using a valid Service Account token #5511

Description

@rafa-acioly

To Reproduce

  1. In Phase Cloud (console.phase.dev), create an app.
  2. Enable SSE (server-side encryption) for the app.
  3. Create a Service Account, attach the app to it, and generate a Service Account token.
  4. In Dokploy, add a new Phase vault provider and paste the Service Account token.
  5. Click Test connection.

Current vs. Expected behavior

Expected: the connection test succeeds.

Actual: the dashboard returns:

[{"error":{"json":{"message":"Phase: authentication failed (status 401: Token expired or deleted)","code":-32600,"data":{"code":"BAD_REQUEST","httpStatus":400,"path":"vaultProvider.testConnection","zodError":null}}}}]

The token is freshly created, not expired, and not revoked.

Provide environment information

Operating System:
  OS: Ubuntu 24.04.4 LTS
  Arch: x86_64
Dokploy version: v0.30.7
VPS Provider: Hetzner
What applications/services are you trying to deploy?
  Phase.dev (Cloud) as secrets/vault provider

Which area(s) are affected? (Select all that apply)

Application, Docker Compose

Are you deploying the applications where Dokploy is installed or on a remote server?

Same server where Dokploy is installed

Additional context

  • Phase Cloud is used, not self-hosted, so the default API host is expected.
  • The request is made server-side by Dokploy, so it can't be seen in the browser DevTools. docker service logs dokploy shows no extra detail about the outbound request (URL, auth header format), so I couldn't debug further.
  • The Phase provider was added in feat(vault): add Phase.dev secrets provider #5123 / feat: add Phase.dev as a secrets provider #5122.
  • Suggestion: log the Phase API URL and the auth scheme used (without the token) when testConnection fails, to make this debuggable.

Will you send a PR to fix it?

Yes

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions