Fix 401 invalid_dsn and DSN 403s on Epure
Public-key auth needs Epure v0.1.5+. Revoked keys return 403 dsn_revoked. The DSN path is a numeric project id.
On this pageShowHide
A 401 invalid_dsn means the sentry_key is missing or invalid, or the Epure binary is older than v0.1.5. From v0.1.5, ingest accepts public-key-only DSN auth. Official Sentry SDKs do not send sentry_secret. EPURE_INGEST_PASSWORD is the Postgres password for the epure_ingest role. SDK requests authenticate with sentry_key. A 403 dsn_revoked means the key was revoked: rotate it and update dsn. A 403 project_mismatch means the key does not belong to the project id in the URL. Copy the DSN from Settings → SDK connection. The path segment is a numeric project id.
Use this if
- Ingest returns 401
invalid_dsnor 403dsn_revoked/project_mismatch @sentry/nodelogsInvalid projectIdand the transport stays disabled- You can recopy the DSN from Settings → SDK connection and recreate the Epure container
Do not use this if
- Ingest returns 202 and Issues stays empty. Use Events not showing
- The hourly cap returns 403
ingest_cap_exceeded. Wait out the hour or raiseingest_cap_per_hour - You need the field-by-field DSN breakdown. That lives on Point the DSN
- You need session replay, distributed tracing, profiling, or a logs product. Those are out of scope
Scope on Epure is exception events. Session replay, distributed tracing, profiling, and a logs product are out of scope. DSN shape: http(s)://{public_key}@{host}/{dsn_project_id} on Point the DSN.
Prerequisites
- Epure image v0.1.5+. Pre-v0.1.5 returns 401
invalid_dsnbecause official SDKs do not sendsentry_secret. - JavaScript pin when you reproduce with the SDK:
@sentry/browserand@sentry/node7.120.0. - The public key and numeric project id from Settings → SDK connection. Dashboard routes look like
/p/:uuid/. That UUID is not the DSN path segment.
Codes
401 invalid_dsn
- Meaning
- Missing or invalid sentry_key, or binary older than v0.1.5
- What to do
- Recopy the public-key DSN. Upgrade to v0.1.5+ and recreate epure
403 dsn_revoked
- Meaning
- Key revoked
- What to do
- Rotate or create a key. Update dsn
403 project_mismatch
- Meaning
- Key does not belong to the URL project id
- What to do
- Use the numeric project id from the DSN you copied
Invalid projectId
- Meaning
- @sentry/node disabled transport. DSN path was the dashboard UUID
- What to do
- Replace the path with the numeric project id. Curl can still hit a UUID path
| Dimension | Meaning | What to do |
|---|---|---|
| 401 invalid_dsn | Missing or invalid sentry_key, or binary older than v0.1.5 | Recopy the public-key DSN. Upgrade to v0.1.5+ and recreate epure |
| 403 dsn_revoked | Key revoked | Rotate or create a key. Update dsn |
| 403 project_mismatch | Key does not belong to the URL project id | Use the numeric project id from the DSN you copied |
| Invalid projectId | @sentry/node disabled transport. DSN path was the dashboard UUID | Replace the path with the numeric project id. Curl can still hit a UUID path |
Copyable checks
The auth header carries sentry_key. EPURE_INGEST_PASSWORD is the Postgres password for the epure_ingest role.
curl -sS -w "\nHTTP %{http_code}\n" -X POST "http://localhost:8080/api/${PROJECT_ID}/envelope/" -H "Content-Type: application/x-sentry-envelope" -H "X-Sentry-Auth: Sentry sentry_version=7, sentry_key=${PUBLIC}" --data-binary @fixtures/sentry/browser/envelope.txt
Sentry.captureException(new Error("Epure verify test"))
Verification
- Curl with a numeric
PROJECT_IDand the public key returnsHTTP 202and a JSON body{ "id": "<event-uuid>" }. - The same exception shows up under the project that owns that DSN.
@sentry/nodeno longer logsInvalid projectId, and the transport stays enabled.
Troubleshooting
Correct public key, still 401 invalid_dsn
The binary is older than v0.1.5. Official SDKs send the public key and omit sentry_secret. Pin a v0.1.5+ image, git pull, and recreate epure. Recopy the DSN from Settings → SDK connection. EPURE_INGEST_PASSWORD stays in Postgres role config.
403 dsn_revoked
Rotate creates a new key and revokes the old one. Old public keys then return 403 dsn_revoked. Update dsn everywhere it is set, including NEXT_PUBLIC_SENTRY_DSN on Next.js, then send the verify exception again.
UUID in the path
Dashboard URLs use an internal UUID (/p/:uuid/). Curl against that UUID can still reach ingest. @sentry/node logs Invalid projectId and disables transport. Copy the DSN again so the path is the numeric project id.
A login form that accepts the password and shows itself again is the HTTP Secure-cookie case in Troubleshooting.