AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

PKCE Flow_state Never Persisted — All New Sign-Ins Fail With Flow_state_not_found

Auth.flow_state table stops receiving new rows after project creation, causing every new PKCE-based sign-in (Google OAuth and magic link) to fail at /token with flow_state_not_found. Existing sessions unaffected; client-side and dashboard config verified correct.

criticalConfidence 65%Supabase Auth (GoTrue)

Origin Analysis

GoTrue is failing to INSERT into auth.flow_state for new sign-ins. The most likely server-side cause is a change in database ownership/grants or a missing column default (e.g., id) that causes silent insert failure. No custom triggers or RLS enforcement on the owner role are present, but a revoked INSERT grant or altered default would match the observed 'no new rows since 2026-06-26' pattern.
1. Configure Supabase project with Google OAuth and email magic link; 2. Initiate PKCE sign-in via createBrowserClient from @supabase/ssr with code_verifier cookie; 3. Observe /authorize returns 302 and external provider redirect; 4. Complete provider callback and call /token with auth_code and code_verifier; 5. /token returns 404 flow_state_not_found; 6. Query auth.flow_state shows no new row created during sign-in.

Fixing Code Block

Edge Case Audit

This is a diagnostic hotfix. If the root cause is different (e.g., GoTrue bug, connection pooler misconfiguration), the fix may not resolve the issue. Before applying, back up auth.flow_state and all auth tables. To roll back, revoke the grants and restore the previous column defaults. Test in a staging project first. Do not run on a production system without a full database backup.

Ecosystem Topology