[GH-ISSUE #7228] Token has expired / Invalid claim #39900

Closed
opened 2026-07-17 20:26:01 -05:00 by GiteaMirror · 3 comments
Owner

Originally created by @sdx010 on GitHub (May 15, 2026).
Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7228

Prerequisites

Vaultwarden Support String

Your environment (Generated via diagnostics page)

  • Vaultwarden version: v1.36.0
  • Web-vault version: v2026.4.1
  • OS/Arch: linux/x86_64
  • Running within a container: true (Base: Debian)
  • Database type: SQLite
  • Database version: 3.51.3
  • Uses config.json: false
  • Uses a reverse proxy: true
  • IP Header check: true (X-Real-IP)
  • Internet access: true
  • Internet access via a proxy: false
  • DNS Check: true
  • TZ environment: Europe/Berlin
  • Browser/Server Time Check: true
  • Server/NTP Time Check: true
  • Domain Configuration Check: true
  • HTTPS Check: true
  • Websocket Check: true
  • HTTP Response Checks: true

Config & Details (Generated via diagnostics page)

Show Config & Details

Config:

{
  "_duo_akey": null,
  "_enable_duo": true,
  "_enable_email_2fa": false,
  "_enable_smtp": true,
  "_enable_yubico": true,
  "_icon_service_csp": "",
  "_icon_service_url": "",
  "_ip_header_enabled": true,
  "_max_note_size": 10000,
  "_smtp_img_src": "***:",
  "admin_ratelimit_max_burst": 3,
  "admin_ratelimit_seconds": 300,
  "admin_session_lifetime": 20,
  "admin_token": "***",
  "allowed_connect_src": "",
  "allowed_iframe_ancestors": "",
  "attachments_folder": "data/attachments",
  "auth_request_purge_schedule": "30 * * * * *",
  "authenticator_disable_time_drift": false,
  "data_folder": "data",
  "database_conn_init": "",
  "database_idle_timeout": 600,
  "database_max_conns": 10,
  "database_min_conns": 2,
  "database_timeout": 30,
  "database_url": "***************",
  "db_connection_retries": 15,
  "disable_2fa_remember": false,
  "disable_admin_token": false,
  "disable_icon_download": false,
  "dns_prefer_ipv6": false,
  "domain": "*****://*************",
  "domain_origin": "*****://*************",
  "domain_path": "",
  "domain_set": true,
  "duo_context_purge_schedule": "30 * * * * *",
  "duo_host": null,
  "duo_ikey": null,
  "duo_skey": null,
  "duo_use_iframe": false,
  "email_2fa_auto_fallback": false,
  "email_2fa_enforce_on_verified_invite": false,
  "email_attempts_limit": 3,
  "email_change_allowed": true,
  "email_expiration_time": 600,
  "email_token_size": 6,
  "emergency_access_allowed": true,
  "emergency_notification_reminder_schedule": "0 3 * * * *",
  "emergency_request_timeout_schedule": "0 7 * * * *",
  "enable_db_wal": true,
  "enable_websocket": true,
  "enforce_single_org_with_reset_pw_policy": false,
  "event_cleanup_schedule": "0 10 0 * * *",
  "events_days_retain": null,
  "experimental_client_feature_flags": "pm-25373-windows-biometrics-v2",
  "extended_logging": true,
  "helo_name": null,
  "hibp_api_key": null,
  "http_request_block_non_global_ips": true,
  "http_request_block_regex": null,
  "icon_blacklist_non_global_ips": true,
  "icon_blacklist_regex": null,
  "icon_cache_folder": "data/icon_cache",
  "icon_cache_negttl": 259200,
  "icon_cache_ttl": 2592000,
  "icon_download_timeout": 10,
  "icon_redirect_code": 302,
  "icon_service": "internal",
  "incomplete_2fa_schedule": "30 * * * * *",
  "incomplete_2fa_time_limit": 3,
  "increase_note_size_limit": false,
  "invitation_expiration_hours": 120,
  "invitation_org_name": "Vaultwarden",
  "invitations_allowed": true,
  "ip_header": "X-Real-IP",
  "job_poll_interval_ms": 30000,
  "log_file": "/data/vaultwarden.log",
  "log_level": "warn",
  "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f",
  "login_ratelimit_max_burst": 10,
  "login_ratelimit_seconds": 60,
  "org_attachment_limit": null,
  "org_creation_users": "",
  "org_events_enabled": false,
  "org_groups_enabled": false,
  "password_hints_allowed": true,
  "password_iterations": 600000,
  "purge_incomplete_sso_auth": "0 20 0 * * *",
  "push_enabled": true,
  "push_identity_uri": "https://identity.bitwarden.eu",
  "push_installation_id": "***",
  "push_installation_key": "***",
  "push_relay_uri": "https://api.bitwarden.eu",
  "reload_templates": false,
  "require_device_email": false,
  "rsa_key_filename": "data/rsa_key",
  "send_purge_schedule": "0 5 * * * *",
  "sendmail_command": null,
  "sends_allowed": true,
  "sends_folder": "data/sends",
  "show_password_hint": false,
  "signups_allowed": false,
  "signups_domains_whitelist": "",
  "signups_verify": false,
  "signups_verify_resend_limit": 6,
  "signups_verify_resend_time": 3600,
  "smtp_accept_invalid_certs": false,
  "smtp_accept_invalid_hostnames": false,
  "smtp_auth_mechanism": null,
  "smtp_debug": false,
  "smtp_embed_images": true,
  "smtp_explicit_tls": null,
  "smtp_from": "************************",
  "smtp_from_name": "***********",
  "smtp_host": "****************",
  "smtp_password": "***",
  "smtp_port": 465,
  "smtp_security": "force_tls",
  "smtp_ssl": null,
  "smtp_timeout": 15,
  "smtp_username": "*********************",
  "sso_allow_unknown_email_verification": false,
  "sso_audience_trusted": null,
  "sso_auth_only_not_session": false,
  "sso_authority": "",
  "sso_authorize_extra_params": "",
  "sso_callback_path": "*****://******************************************",
  "sso_client_cache_expiration": 0,
  "sso_client_id": "",
  "sso_client_secret": "***",
  "sso_debug_tokens": false,
  "sso_enabled": false,
  "sso_master_password_policy": null,
  "sso_only": false,
  "sso_pkce": true,
  "sso_scopes": "email profile",
  "sso_signups_match_email": true,
  "templates_folder": "data/templates",
  "tmp_folder": "data/tmp",
  "trash_auto_delete_days": null,
  "trash_purge_schedule": "0 5 0 * * *",
  "use_sendmail": false,
  "use_syslog": false,
  "user_attachment_limit": null,
  "user_send_limit": null,
  "web_vault_enabled": true,
  "web_vault_folder": "web-vault/",
  "yubico_client_id": null,
  "yubico_secret_key": null,
  "yubico_server": null
}

Vaultwarden Build Version

v1.36.0

Deployment method

Official Container Image

Custom deployment method

No response

Reverse Proxy

nginx-proxy-manager v2.14.0

Host/Server Operating System

Linux

Operating System Version

Debian 12

Clients

iOS

Client Version

2025.4.1

Steps To Reproduce

  1. Open the iOS app (version 2025.4.1)
  2. Login
  3. Check logs for authentication errors

Expected Result

Authenticate successfully without token or claim validation errors

Actual Result

Token has expired
Invalid claim
Request guard failure for headers

Logs

[2026-05-15 12:27:17.058][vaultwarden::auth][ERROR] Token has expired
[2026-05-15 12:27:17.058][auth][ERROR] Unauthorized Error: Invalid claim
[2026-05-15 12:27:17.058][vaultwarden::api::core::accounts::_][WARN] Request guard `Headers` failed: "Invalid claim".

Screenshots or Videos

No response

Additional Context

Since updating the iOS app to version 2025.4.1, I’m seeing authentication-related errors in the logs. The issue only happens on iOS, everything works fine on the desktop app and in the web vault.

Even though the errors appear, the iOS app itself still seems to work normally and I can continue using it without obvious problems.

Troubleshooting already performed:
Reinstalled the iOS app (including cache removal)
Deauthorized all devices in the web vault
Logged in again on iOS
Remove rsa_key.pem

Originally created by @sdx010 on GitHub (May 15, 2026). Original GitHub issue: https://github.com/dani-garcia/vaultwarden/issues/7228 ### Prerequisites - [x] I have searched the existing **Closed _AND_ Open** [Issues](https://github.com/dani-garcia/vaultwarden/issues?q=is%3Aissue%20) **_AND_** [Discussions](https://github.com/dani-garcia/vaultwarden/discussions?discussions_q=) - [x] I have searched and read the [documentation](https://github.com/dani-garcia/vaultwarden/wiki/) ### Vaultwarden Support String ### Your environment (Generated via diagnostics page) * Vaultwarden version: v1.36.0 * Web-vault version: v2026.4.1 * OS/Arch: linux/x86_64 * Running within a container: true (Base: Debian) * Database type: SQLite * Database version: 3.51.3 * Uses config.json: false * Uses a reverse proxy: true * IP Header check: true (X-Real-IP) * Internet access: true * Internet access via a proxy: false * DNS Check: true * TZ environment: Europe/Berlin * Browser/Server Time Check: true * Server/NTP Time Check: true * Domain Configuration Check: true * HTTPS Check: true * Websocket Check: true * HTTP Response Checks: true ### Config & Details (Generated via diagnostics page) <details><summary>Show Config & Details</summary> **Config:** ```json { "_duo_akey": null, "_enable_duo": true, "_enable_email_2fa": false, "_enable_smtp": true, "_enable_yubico": true, "_icon_service_csp": "", "_icon_service_url": "", "_ip_header_enabled": true, "_max_note_size": 10000, "_smtp_img_src": "***:", "admin_ratelimit_max_burst": 3, "admin_ratelimit_seconds": 300, "admin_session_lifetime": 20, "admin_token": "***", "allowed_connect_src": "", "allowed_iframe_ancestors": "", "attachments_folder": "data/attachments", "auth_request_purge_schedule": "30 * * * * *", "authenticator_disable_time_drift": false, "data_folder": "data", "database_conn_init": "", "database_idle_timeout": 600, "database_max_conns": 10, "database_min_conns": 2, "database_timeout": 30, "database_url": "***************", "db_connection_retries": 15, "disable_2fa_remember": false, "disable_admin_token": false, "disable_icon_download": false, "dns_prefer_ipv6": false, "domain": "*****://*************", "domain_origin": "*****://*************", "domain_path": "", "domain_set": true, "duo_context_purge_schedule": "30 * * * * *", "duo_host": null, "duo_ikey": null, "duo_skey": null, "duo_use_iframe": false, "email_2fa_auto_fallback": false, "email_2fa_enforce_on_verified_invite": false, "email_attempts_limit": 3, "email_change_allowed": true, "email_expiration_time": 600, "email_token_size": 6, "emergency_access_allowed": true, "emergency_notification_reminder_schedule": "0 3 * * * *", "emergency_request_timeout_schedule": "0 7 * * * *", "enable_db_wal": true, "enable_websocket": true, "enforce_single_org_with_reset_pw_policy": false, "event_cleanup_schedule": "0 10 0 * * *", "events_days_retain": null, "experimental_client_feature_flags": "pm-25373-windows-biometrics-v2", "extended_logging": true, "helo_name": null, "hibp_api_key": null, "http_request_block_non_global_ips": true, "http_request_block_regex": null, "icon_blacklist_non_global_ips": true, "icon_blacklist_regex": null, "icon_cache_folder": "data/icon_cache", "icon_cache_negttl": 259200, "icon_cache_ttl": 2592000, "icon_download_timeout": 10, "icon_redirect_code": 302, "icon_service": "internal", "incomplete_2fa_schedule": "30 * * * * *", "incomplete_2fa_time_limit": 3, "increase_note_size_limit": false, "invitation_expiration_hours": 120, "invitation_org_name": "Vaultwarden", "invitations_allowed": true, "ip_header": "X-Real-IP", "job_poll_interval_ms": 30000, "log_file": "/data/vaultwarden.log", "log_level": "warn", "log_timestamp_format": "%Y-%m-%d %H:%M:%S.%3f", "login_ratelimit_max_burst": 10, "login_ratelimit_seconds": 60, "org_attachment_limit": null, "org_creation_users": "", "org_events_enabled": false, "org_groups_enabled": false, "password_hints_allowed": true, "password_iterations": 600000, "purge_incomplete_sso_auth": "0 20 0 * * *", "push_enabled": true, "push_identity_uri": "https://identity.bitwarden.eu", "push_installation_id": "***", "push_installation_key": "***", "push_relay_uri": "https://api.bitwarden.eu", "reload_templates": false, "require_device_email": false, "rsa_key_filename": "data/rsa_key", "send_purge_schedule": "0 5 * * * *", "sendmail_command": null, "sends_allowed": true, "sends_folder": "data/sends", "show_password_hint": false, "signups_allowed": false, "signups_domains_whitelist": "", "signups_verify": false, "signups_verify_resend_limit": 6, "signups_verify_resend_time": 3600, "smtp_accept_invalid_certs": false, "smtp_accept_invalid_hostnames": false, "smtp_auth_mechanism": null, "smtp_debug": false, "smtp_embed_images": true, "smtp_explicit_tls": null, "smtp_from": "************************", "smtp_from_name": "***********", "smtp_host": "****************", "smtp_password": "***", "smtp_port": 465, "smtp_security": "force_tls", "smtp_ssl": null, "smtp_timeout": 15, "smtp_username": "*********************", "sso_allow_unknown_email_verification": false, "sso_audience_trusted": null, "sso_auth_only_not_session": false, "sso_authority": "", "sso_authorize_extra_params": "", "sso_callback_path": "*****://******************************************", "sso_client_cache_expiration": 0, "sso_client_id": "", "sso_client_secret": "***", "sso_debug_tokens": false, "sso_enabled": false, "sso_master_password_policy": null, "sso_only": false, "sso_pkce": true, "sso_scopes": "email profile", "sso_signups_match_email": true, "templates_folder": "data/templates", "tmp_folder": "data/tmp", "trash_auto_delete_days": null, "trash_purge_schedule": "0 5 0 * * *", "use_sendmail": false, "use_syslog": false, "user_attachment_limit": null, "user_send_limit": null, "web_vault_enabled": true, "web_vault_folder": "web-vault/", "yubico_client_id": null, "yubico_secret_key": null, "yubico_server": null } ``` </details> ### Vaultwarden Build Version v1.36.0 ### Deployment method Official Container Image ### Custom deployment method _No response_ ### Reverse Proxy nginx-proxy-manager v2.14.0 ### Host/Server Operating System Linux ### Operating System Version Debian 12 ### Clients iOS ### Client Version 2025.4.1 ### Steps To Reproduce 1. Open the iOS app (version 2025.4.1) 2. Login 3. Check logs for authentication errors ### Expected Result Authenticate successfully without token or claim validation errors ### Actual Result Token has expired Invalid claim Request guard failure for headers ### Logs ```text [2026-05-15 12:27:17.058][vaultwarden::auth][ERROR] Token has expired [2026-05-15 12:27:17.058][auth][ERROR] Unauthorized Error: Invalid claim [2026-05-15 12:27:17.058][vaultwarden::api::core::accounts::_][WARN] Request guard `Headers` failed: "Invalid claim". ``` ### Screenshots or Videos _No response_ ### Additional Context Since updating the iOS app to version 2025.4.1, I’m seeing authentication-related errors in the logs. The issue only happens on iOS, everything works fine on the desktop app and in the web vault. Even though the errors appear, the iOS app itself still seems to work normally and I can continue using it without obvious problems. Troubleshooting already performed: Reinstalled the iOS app (including cache removal) Deauthorized all devices in the web vault Logged in again on iOS Remove rsa_key.pem
GiteaMirror added the bug label 2026-07-17 20:26:01 -05:00
Author
Owner

@BlackDex commented on GitHub (May 15, 2026):

It might be that your iOS device still had an old token, and not sure if you recently updated from an older version, but that could have caused this too.

Also, removing the rsa_key.pem will cause this for all devices.
So, please test again, try to logout, reboot the phone, and login again after the file has been removed.

Also, try to enable the Flight Record and see if there is anything useful in the report generated from there.

I'm not able to test this my self as I do not have an iOS device currently to test with.

<!-- gh-comment-id:4460004815 --> @BlackDex commented on GitHub (May 15, 2026): It might be that your iOS device still had an old token, and not sure if you recently updated from an older version, but that could have caused this too. Also, removing the `rsa_key.pem` will cause this for all devices. So, please test again, try to logout, reboot the phone, and login again after the file has been removed. Also, try to enable the Flight Record and see if there is anything useful in the report generated from there. I'm not able to test this my self as I do not have an iOS device currently to test with.
Author
Owner

@sdx010 commented on GitHub (May 15, 2026):

I logged out from all devices, rebooted my iPhone, and logged in again, but the authentication errors are still appearing in the logs.

To rule out any issues with my existing setup, I also created a completely fresh Vaultwarden instance with a new database and tested it with an iOS device that had never been connected to Vaultwarden before. Even with this clean setup, the same errors still occur.
I also tried the latest Vaultwarden Testing image, but there was no difference there either.

I even restored my entire server from a 3 month old backup where I am sure these errors did not exist yet, but the issue is still present there as well. At least this finally gave me a chance to verify that my backups are actually working properly.

...ups! I forgot to enable the flight record in the app. It usually takes about an hour for the errors to reappear in the logs. I’ll post the flight recorder logs as soon as I have them.

<!-- gh-comment-id:4462614231 --> @sdx010 commented on GitHub (May 15, 2026): I logged out from all devices, rebooted my iPhone, and logged in again, but the authentication errors are still appearing in the logs. To rule out any issues with my existing setup, I also created a completely fresh Vaultwarden instance with a new database and tested it with an iOS device that had never been connected to Vaultwarden before. Even with this clean setup, the same errors still occur. I also tried the latest Vaultwarden Testing image, but there was no difference there either. I even restored my entire server from a 3 month old backup where I am sure these errors did not exist yet, but the issue is still present there as well. At least this finally gave me a chance to verify that my backups are actually working properly. ...ups! I forgot to enable the flight record in the app. It usually takes about an hour for the errors to reappear in the logs. I’ll post the flight recorder logs as soon as I have them.
Author
Owner

@sdx010 commented on GitHub (May 16, 2026):

I can’t reproduce the issue anymore. After a lot of back and forth with logging in/out, reinstalling the iOS app, and testing both my existing setup and a completely fresh Vaultwarden instance (including an old backup), I honestly lost track of what actually fixed it.

My current guess is that the forced restart of the iPhone (Volume Up → Volume Down → hold the Side button until the Apple logo appears) might have played a role. The error showed up once more after that, but since then it has not reappeared.
Maybe this will help someone else running into the same problem.

What still bothers me, is why this happened in the first place, since I was able to reproduce it even with a clean server, a fresh database, and a different iOS device.

<!-- gh-comment-id:4467082866 --> @sdx010 commented on GitHub (May 16, 2026): I can’t reproduce the issue anymore. After a lot of back and forth with logging in/out, reinstalling the iOS app, and testing both my existing setup and a completely fresh Vaultwarden instance (including an old backup), I honestly lost track of what actually fixed it. My current guess is that the forced restart of the iPhone (Volume Up → Volume Down → hold the Side button until the Apple logo appears) might have played a role. The error showed up once more after that, but since then it has not reappeared. Maybe this will help someone else running into the same problem. What still bothers me, is why this happened in the first place, since I was able to reproduce it even with a clean server, a fresh database, and a different iOS device.
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: github-starred/vaultwarden#39900