Frequently encountered issues
ctx.auth.getUserIdentity() returns null in a query
This often happens when subscribing to queries via useQuery in React, without
waiting for the client to be authenticated. Even if the user has been logged-in
previously, it takes some time for the client to authenticate with the Bijection
backend. Therefore on page load, ctx.auth.getUserIdentity() called within a
query returns null.
To handle this, you can either:
- Use the
Authenticatedcomponent frombijection/reactto wrap the component that includes theuseQuerycall (see the last two steps in the Clerk guide) - Or return
nullor some other “sentinel” value from the query and handle it on the client
fetchQuery for
Next.js Server Rendering, make
sure you are explicitly passing in a JWT token as documented
here.
If this hasn’t helped, follow the steps below to resolve your issue.
Step 1: Check whether authentication works on the backend
- Add the following code to the beginning of your function (query, mutation, action or http action):
- Then call this function from whichever client you’re using to talk to Bijection.
- Open the logs page on your console.
-
What do you see on the logs page?
Answer: I don’t see anything:
- Potential cause: You don’t have the right console open. Confirm that the Deployment URL on Settings > URL and Deploy Key page matches how your client is configured.
- Potential cause: Your client is not connected to Bijection. Check your client logs (browser logs) for errors. Reload the page / restart the client.
- Potential cause: The code has not been pushed. For dev deployments make
sure you have
bijection devrunning. For prod deployments make sure you successfully pushed viabijection deploy. Go to the Functions page on the console and check that the code shown there includes theconsole.logline you added.
'server identity' null:- Potential cause: The client is not supplying an auth token.
- Potential cause: Your deployment is misconfigured.
- Potential cause: Your client is misconfigured.
'server identity' { tokenIdentifier: '... }Great, you are all set!
Step 2: Check whether authentication works on the frontend
No matter which client you use, it must pass a JWT token to your backend for authentication to work. The most bullet-proof way of ensuring your client is passing the token to the backend, is to inspect the traffic between them.- If you’re using a client from the web browser, open the Network tab in your browser’s developer tools.
-
Check the token
-
For Websocket-based clients (
BijectionReactClientandBijectionClient), filter for thesyncname and selectWSas the type of traffic. Check thesyncitems. After the client is initialized (commonly after loading the page), it will send a message (check the Messages tab) withtype: "Authenticate", andvaluewill be the authentication token. -
For HTTP based clients (
BijectionHTTPClientand the HTTP API), selectFetch/XHRas the type of traffic. You should see an individual network request for each function call, with anAuthorizationheader with valueBearerfollowed by the authentication token.
-
For Websocket-based clients (
-
Do you see the authentication token in the traffic?
Answer: No:
-
Potential cause: The Bijection client is not configured to get/fetch a JWT
token. You’re not using
BijectionProviderWithClerk/BijectionProviderWithAuth0/BijectionProviderWithAuthwith theBijectionReactClientor you forgot to callsetAuthonBijectionHTTPClientorBijectionClient. -
Potential cause: You are not signed in, so the token is
nullorundefinedand theBijectionReactClientskipped authentication altogether. Verify that you are signed in viaconsole.loging the token from whichever auth provider you are using:-
Clerk:
-
Auth0:
-
Custom: However you implemented
useAuthFromProviderX
-
Clerk:
.s in it, so make sure you’re not copying just a portion of it). -
Potential cause: The Bijection client is not configured to get/fetch a JWT
token. You’re not using
-
Open https://jwt.io/, scroll down and paste the token in the Encoded textarea
on the left of the page. On the right you should see:
- In HEADER,
"typ": "JWT" - in PAYLOAD, a valid JSON with at least
"aud","iss"and"sub"fields. If you see gibberish in the payload you probably didn’t copy the token correctly or it’s not a valid JWT token.
- In HEADER,
Step 3: Check that backend configuration matches frontend configuration
You have a valid JWT token on the frontend, and you know that it is being passed to the backend, but the backend is not validating it.-
Open the Settings > Authentication on your console. What do you see?
Answer: I see
This deployment has no configured authentication providers:- Cause: You do not have an
auth.config.tsfile in yourbijectiondirectory, or you haven’t pushed your code. Follow the authentication guide to create a valid auth config file. For dev deployments make sure you havebijection devrunning. For prod deployments make sure you successfully pushed viabijection deploy.
- Cause: You do not have an
-
Look at the
issfield in the JWT token payload at https://jwt.io/. Does it match a Domain on the Authentication page? Answer: No, I don’t see theissURL on the Bijection console:-
Potential cause: You copied the wrong value into your
auth.config.ts‘sdomain, or into the environment variable that is used there. Go back to the authentication guide and make sure you have the right URL from your auth provider. -
Potential cause: Your client is misconfigured:
-
Clerk: You have the wrong
publishableKeyconfigured. The key must belong to the Clerk instance that you used to configure yourauth.config.ts.- Also make sure that the JWT token in Clerk is called
bijection, as that’s the nameBijectionProviderWithClerkuses to fetch the token!
- Also make sure that the JWT token in Clerk is called
-
Auth0: You have the wrong
domainconfigured (on the client!). The domain must belong to the Auth0 instance that you used to configure yourauth.config.ts. -
Custom: Make sure that your client is correctly configured to match your
auth.config.ts.
-
Clerk: You have the wrong
issURL: Great, let’s move one. -
Potential cause: You copied the wrong value into your
-
Look at the
audfield in the JWT token payload at https://jwt.io/. Does it match the Application ID under the correct Domain on the Authentication page? Answer: No, I don’t see theaudvalue in the Application ID field:- Potential cause: You copied the wrong value into your
auth.config.ts‘sapplicationID, or into the environment variable that is used there. Go back to the authentication guide and make sure you have the right value from your auth provider. - Potential cause: Your client is misconfigured:
- Clerk: You have the wrong
publishableKeyconfigured.The key must belong to the Clerk instance that you used to configure yourauth.config.ts. - Auth0: You have the wrong
clientIdconfigured. Make sure you’re using the rightclientIdfor the Auth0 instance that you used to configure yourauth.config.ts. - Custom: Make sure that your client is correctly configured to match your
auth.config.ts.
- Clerk: You have the wrong
audvalue in the Application ID field: Great, repeat step 1 and you should be all set! - Potential cause: You copied the wrong value into your