Repeated 401 or 403 errors after sign-in

Use this article when screens such as Audit Log, Passwords, Updates, Users or Browser Extension show access errors or empty data right after login.

Expected behavior in VaultPilot 3.0.3

VaultPilot confirms the new session with the server before it treats the vault as unlocked, and the session survives page refreshes until it times out. Workspace screens load only after that confirmation. If the session cannot be confirmed, the screen locks and clears cached data instead of retrying again and again.

First checks

CheckHealthy result
Installed versionThe console reports VaultPilot 3.0.3 or newer. Move older deployments to the current official release before contacting support.
LoginSign-in completes without an error message.
SessionThe workspace opens unlocked after sign-in and stays unlocked after a refresh.
Workspace screensAudit, passwords, browser extension, updates, users and integrations load their data.
Browser modeCookies are not blocked for the VaultPilot host.
Address consistencyLogin and workspace use the same host, https and port.

Common causes

  • The browser blocks or clears the session cookie.
  • The operator signs in through one host name but continues through another host name or IP.
  • A service restart ended the current session.
  • An old tab keeps refreshing screens after the user was locked.
  • A reverse proxy changes the cookie, host or https handling.

Safe evidence to collect

  • VaultPilot version, plus the legacy PassMan version only for upgraded installs.
  • Host name replaced by <SERVER_HOST>.
  • Whether the workspace stays unlocked after sign-in.
  • Which screens fail and the error message they show.
  • Browser family and whether cookies are blocked.
  • Whether the issue appears after refresh, service restart, update or host change.

Do not send master passwords, cookies, session token values, screenshots with real records or raw logs with secret values.

Resolution path

  1. Install or upgrade to the official VaultPilot 3.0.3 release or newer.
  2. Sign out, close old tabs and open VaultPilot from one address.
  3. Confirm browser cookies are allowed for the VaultPilot host.
  4. Sign in again and check whether the workspace stays unlocked before opening other screens.
  5. If a proxy is used, confirm it keeps the host, https and cookies unchanged.
  6. If the issue continues, email the safe evidence pack to support@vaultpilot.io.

Still stuck?

Check the troubleshooting guide, then write to support@vaultpilot.io with the version, the steps you took and the exact redacted error. Never attach passwords, vault exports or private keys.

Open the troubleshooting guide

Back to Knowledge base