Epure
Guide

Fix 401 invalid_dsn and DSN 403s on Epure

Public-key auth needs Epure v0.1.5+. Revoked keys return 403 dsn_revoked. The DSN path is a numeric project id.

On this pageShow
  1. Prerequisites
  2. Codes
  3. Copyable checks
  4. Verification
  5. Troubleshooting
  6. Questions

A 401 invalid_dsn means the sentry_key is missing or invalid, or the Epure binary is older than v0.1.5. From v0.1.5, ingest accepts public-key-only DSN auth. Official Sentry SDKs do not send sentry_secret. EPURE_INGEST_PASSWORD is the Postgres password for the epure_ingest role. SDK requests authenticate with sentry_key. A 403 dsn_revoked means the key was revoked: rotate it and update dsn. A 403 project_mismatch means the key does not belong to the project id in the URL. Copy the DSN from Settings → SDK connection. The path segment is a numeric project id.

Use this if

  • Ingest returns 401 invalid_dsn or 403 dsn_revoked / project_mismatch
  • @sentry/node logs Invalid projectId and the transport stays disabled
  • You can recopy the DSN from Settings → SDK connection and recreate the Epure container

Do not use this if

  • Ingest returns 202 and Issues stays empty. Use Events not showing
  • The hourly cap returns 403 ingest_cap_exceeded. Wait out the hour or raise ingest_cap_per_hour
  • You need the field-by-field DSN breakdown. That lives on Point the DSN
  • You need session replay, distributed tracing, profiling, or a logs product. Those are out of scope

Scope on Epure is exception events. Session replay, distributed tracing, profiling, and a logs product are out of scope. DSN shape: http(s)://{public_key}@{host}/{dsn_project_id} on Point the DSN.

Prerequisites

  • Epure image v0.1.5+. Pre-v0.1.5 returns 401 invalid_dsn because official SDKs do not send sentry_secret.
  • JavaScript pin when you reproduce with the SDK: @sentry/browser and @sentry/node 7.120.0.
  • The public key and numeric project id from Settings → SDK connection. Dashboard routes look like /p/:uuid/. That UUID is not the DSN path segment.

Codes

DSN auth failures

401 invalid_dsn

Meaning
Missing or invalid sentry_key, or binary older than v0.1.5
What to do
Recopy the public-key DSN. Upgrade to v0.1.5+ and recreate epure

403 dsn_revoked

Meaning
Key revoked
What to do
Rotate or create a key. Update dsn

403 project_mismatch

Meaning
Key does not belong to the URL project id
What to do
Use the numeric project id from the DSN you copied

Invalid projectId

Meaning
@sentry/node disabled transport. DSN path was the dashboard UUID
What to do
Replace the path with the numeric project id. Curl can still hit a UUID path
DimensionMeaningWhat to do
401 invalid_dsnMissing or invalid sentry_key, or binary older than v0.1.5Recopy the public-key DSN. Upgrade to v0.1.5+ and recreate epure
403 dsn_revokedKey revokedRotate or create a key. Update dsn
403 project_mismatchKey does not belong to the URL project idUse the numeric project id from the DSN you copied
Invalid projectId@sentry/node disabled transport. DSN path was the dashboard UUIDReplace the path with the numeric project id. Curl can still hit a UUID path

Copyable checks

The auth header carries sentry_key. EPURE_INGEST_PASSWORD is the Postgres password for the epure_ingest role.

curl -sS -w "\nHTTP %{http_code}\n" -X POST "http://localhost:8080/api/${PROJECT_ID}/envelope/" -H "Content-Type: application/x-sentry-envelope" -H "X-Sentry-Auth: Sentry sentry_version=7, sentry_key=${PUBLIC}" --data-binary @fixtures/sentry/browser/envelope.txt

Sentry.captureException(new Error("Epure verify test"))

Verification

  • Curl with a numeric PROJECT_ID and the public key returns HTTP 202 and a JSON body { "id": "<event-uuid>" }.
  • The same exception shows up under the project that owns that DSN.
  • @sentry/node no longer logs Invalid projectId, and the transport stays enabled.

Troubleshooting

Correct public key, still 401 invalid_dsn

The binary is older than v0.1.5. Official SDKs send the public key and omit sentry_secret. Pin a v0.1.5+ image, git pull, and recreate epure. Recopy the DSN from Settings → SDK connection. EPURE_INGEST_PASSWORD stays in Postgres role config.

403 dsn_revoked

Rotate creates a new key and revokes the old one. Old public keys then return 403 dsn_revoked. Update dsn everywhere it is set, including NEXT_PUBLIC_SENTRY_DSN on Next.js, then send the verify exception again.

UUID in the path

Dashboard URLs use an internal UUID (/p/:uuid/). Curl against that UUID can still reach ingest. @sentry/node logs Invalid projectId and disables transport. Copy the DSN again so the path is the numeric project id.

A login form that accepts the password and shows itself again is the HTTP Secure-cookie case in Troubleshooting.

Questions

Why did public-key DSNs start working at v0.1.5?
v0.1.5+ accepts public-key-only DSN auth. Pre-v0.1.5 returns 401 invalid_dsn because official SDKs do not send sentry_secret.
Is EPURE_INGEST_PASSWORD the DSN secret?
EPURE_INGEST_PASSWORD is the Postgres password for the epure_ingest role. SDK auth uses sentry_key from Settings → SDK connection.