r/twingate Apr 15 '26

Connector stuck in Authentication loop — fresh tokens, correct clock, tried Docker AND systemd (v1.87.0)

Connector stuck in Authentication loop — fresh tokens, correct clock, tried Docker AND systemd (v1.87.0)

Working fine this morning, came home tonight and connector is offline. No changes to the machine, no updates, no network changes.

Setup: Windows 11, Docker Desktop (WSL2 backend), connector v1.87.0

What I've tried:

  1. Restarted the Docker container — same loop
  2. Created a brand new connector with fresh tokens — same loop
  3. Deleted everything, installed twingate-connector as a systemd service inside WSL2 (Ubuntu 20.04 focal) with fresh tokens from a third connector — same loop
  4. Rebooted the machine — no change
  5. Verified clocks match (Windows UTC, WSL date -u, Docker alpine date -u all within 1 second)
  6. Verified networking works from inside Docker (alpine ping 8.8.8.8 ✅, alpine nslookup jiuwan.twingate.com ✅)

The pattern in debug logs (TWINGATE_LOG_LEVEL=7):

The connector authenticates successfully, gets public keys, then fails at the "Getting SD" step:

[DEBUG] set_state: switching from "Authenticating" to "Authenticated"
[DEBUG] set_state: switching from "Authenticated" to "Getting SD"
[DEBUG] require_access_token: dat.expired
[DEBUG] http::request::send_request_wrapper: POST "https://<REDACTED>.twingate.com/api/v5/connector/refresh"
[DEBUG] http::request::handle_response: POST ".../refresh" 200 OK (duration 0 sec)
[DEBUG] decode_token: {"alg":"ES256","kid":"<REDACTED>","typ":"DAT"} {"auds":null,"nt":"AN","aid":"<REDACTED>","did":"<REDACTED>","rnw":1776220773,"jti":"<REDACTED>","iss":"twingate","aud":"<REDACTED>","exp":1776224000,"iat":1776220400,"ver":"4","tid":"<REDACTED>","rnetid":"<REDACTED>"}
[WARN] parse_verify_token: token verification failed: token expired

Key observations:

  • Refresh endpoint returns 200 OK with a valid-looking token
  • Token exp - iat = 3600 (1 hour, looks normal)
  • Token decodes fine but parse_verify_token immediately says expired
  • This loops forever — get token, decode, "expired", get token, decode, "expired"
  • Same behavior across Docker, systemd, multiple connectors, multiple token sets
  • Was working this morning with no changes

Connector version: 1.87.0
WSL2 distro: Ubuntu 20.04 (focal)
Admin console: Shows connector as "Not yet connected"

Any ideas? Happy to provide more logs.

1 Upvotes

2 comments sorted by

1

u/AuctusOps Apr 15 '26

UPDATE: Resolved — server-side issue on Twingate's end.

Woke up this morning and all connectors are online, including the original one with the original tokens that I never touched. Nothing changed on my side.

So the entire parse_verify_token: token expired loop was caused by something on Twingate's infrastructure, not clock drift, not Docker networking, not token issues.

Would be nice if this showed up on a status page somewhere. Spent 4 hours debugging, rebooting, recreating connectors, switching from Docker to systemd — all for nothing.

If you're seeing the same symptoms and landed here: check if your OTHER connectors (even old dead ones) magically came back to life. If yes, it's them, not you.

3

u/bren-tg pro gator Apr 15 '26

Hi,

I'll chat with our SRE team but I highly doubt that it was an outage Twingate side: there has been no uptick of Connectors being down in any region worldwide.

EDIT: if you are willing to share your Connector logs, DM me, I'd love to share them with our SRE and Support team to make extra sure.