AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

PGRST303 'JWT Issued At Future' Due To Clock Skew Between API Gateway And PostgREST When Using Sb_secret_ Keys

Intermittent 401 PGRST303 errors occur because the Supabase API gateway mints a short-lived JWT with an iat claim based on its own clock, which can be ahead of the PostgREST instance's clock by more than the default validation leeway, causing PostgREST to reject the token as issued in the future.

highConfidence 88%Supabase

Origin Analysis

Clock skew between the Supabase API gateway and the PostgREST instance exceeds the JWT iat future-tolerance (leeway) configured in PostgREST. The gateway exchanges the opaque sb_secret_ key for a JWT with iat set to the gateway's current time; if the gateway clock is ahead of PostgREST by more than the allowed leeway (often 0-1 seconds), PostgREST rejects the token with PGRST303. The intermittent nature and occasional >2s skew matches the observed retry failures.
1. Use a valid new-format `sb_secret_` key with server-side supabase-js. 2. Send multiple REST requests (e.g., selects) over an extended period. 3. Observe intermittent HTTP 401 with body `PGRST303 - JWT issued at future`. 4. The error is not reproducible on demand and appears related to cross-component clock skew.

Fixing Code Block

Edge Case Audit

Increasing the skew compensation reduces the effective indication of issuance time and slightly extends the window during which a token may be considered valid if an attacker captures it; however, since the token is signed by Supabase and short-lived, this is low risk. Ensure the skew compensation is not set arbitrarily high (e.g., >30s) to avoid tokens being accepted after a potential revocation or secret rotation. Rollback is straightforward by removing or reducing the `JWT_SKEW_SECONDS` env var. If using PostgREST leeway, be aware it applies to all JWT validation, including externally supplied tokens, which could weaken future-iat rejection.

Ecosystem Topology