File size: 582 Bytes
29fdac9
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
# Auth 401/403

## Symptoms
- API returns 401/403 for valid requests
- `Invalid token`, `permission denied`, or `signature mismatch` in logs
- Clock skew errors in authentication service

## Checks
- Validate access token expiration and issuer
- Confirm user/service account scopes/roles
- Check client/server clock skew (NTP)
- Review recent secret/credential rotations
- Inspect identity provider availability and rate limits

## Fix
- Refresh/rotate tokens or credentials
- Grant correct roles/scopes to caller
- Align clocks and retry
- Apply retry/backoff if IDP is throttling