# rpc error: code = PermissionDenied desc = authentication failed: invalid token

- **ID:** `go/grpc-permission-denied-auth`
- **Domain:** go
- **Category:** auth_error
- **Verification:** ai_generated
- **Fix Rate:** 80%

## Root Cause

The client provided an invalid or expired authentication token, or the server's authentication middleware rejected the credentials.

## Version Compatibility

| Version | Status | Introduced | Deprecated |
|---------|--------|------------|------------|
| 1.x | active | — | — |

## Workarounds

1. **** (90% success)
   ```
   // Use a token source that refreshes automatically
ts := oauth.NewTokenSource(ctx, config)
creds := oauth.NewOauthAccess(token)
conn, err := grpc.Dial(addr, grpc.WithPerRPCCredentials(creds))
   ```
2. **** (85% success)
   ```
   // Server interceptor to validate token
func authInterceptor(ctx context.Context, req interface{}, info *grpc.UnaryServerInfo, handler grpc.UnaryHandler) (interface{}, error) {
    token, err := extractToken(ctx)
    if err != nil || !validateToken(token) {
        return nil, status.Errorf(codes.PermissionDenied, "invalid token")
    }
    return handler(ctx, req)
}
   ```

## Dead Ends

- **** — This is a security risk and not a proper fix; it may violate compliance requirements. (95% fail)
- **** — The token is invalid; retrying won't change the outcome. (100% fail)
