# Dial failed: invalid api session id

**URL:** <https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056>\
**Category:** zrok\
**Created:** [August 25, 2025, 6:10pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056 "2025-08-25T18:10:46Z")\
**Posts on this page:** 15\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [August 25, 2025, 6:10pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/1 "2025-08-25T18:10:46Z")

</div>

```auto
{
  "file": "/__w/zrok/zrok/agent/accessPrivate.go:45",
  "func": "github.com/openziti/zrok/agent.(*Agent).AccessPrivate.func1",
  "level": "info",
  "msg": "map[file:/__w/zrok/zrok/endpoints/proxy/frontend.go:133 func:github.com/openziti/zrok/endpoints/proxy.newServiceProxy.func3 level:error msg:error proxying: unable to dial service 'myproxy' (dial failed: invalid api session id, expected 6946e35b-df7f...., got 0777e9cd-....) time:2025-08-25T20:00:12.557331236+02:00]",
  "time": "2025-08-25T20:00:29.397Z"
}

{
  "file": "/__w/zrok/zrok/agent/accessPrivate.go:45",
  "func": "github.com/openziti/zrok/agent.(*Agent).AccessPrivate.func1",
  "level": "info",
  "msg": "map[file:/__w/zrok/zrok/endpoints/tcpTunnel/frontend.go:91 func:github.com/openziti/zrok/endpoints/tcpTunnel.(*Frontend).accept level:error msg:error dialing 'mytunnel': unable to dial service 'mytunnel' (dial failed: invalid api session id, expected b74a458a-....., got fc12ba49-.....) time:2025-08-25T20:03:14.275503887+02:00]",
  "time": "2025-08-25T20:03:14.626Z"
}

```

zrok 1.1.3 needs to be restarted

---

<div class="post-metadata">

**Author:** ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)\
**Post date:** [August 25, 2025, 6:12pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/2 "2025-08-25T18:12:50Z")

</div>

Try turning off “super network” and report back.

---

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [August 25, 2025, 6:48pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/3 "2025-08-25T18:48:58Z")

</div>

The same problem with 1.1.3 even after:

zrok config set superNetwork false

systemctl --user restart zrok-agent.service

```auto
{
  "file": "/__w/zrok/zrok/agent/accessPrivate.go:45",
  "func": "github.com/openziti/zrok/agent.(*Agent).AccessPrivate.func1",
  "level": "info",
  "msg": "map[file:/__w/zrok/zrok/endpoints/proxy/frontend.go:133 func:github.com/openziti/zrok/endpoints/proxy.newServiceProxy.func3 level:error msg:error proxying: unable to dial service 'myproxy' (dial failed: invalid api session id, expected d1a57560-..., got 2f9309e8-....) time:2025-08-25T20:42:56.768290676+02:00]",
  "time": "2025-08-25T20:42:57.174Z"
}

```

zrok 1.1.2 does not have this problem.

---

<div class="post-metadata">

**Author:** ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)\
**Post date:** [August 25, 2025, 7:21pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/4 "2025-08-25T19:21:20Z")

</div>

The only material difference between zrok 1.1.2 and 1.1.3 is the embedded Ziti SDK version.

---

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [August 25, 2025, 7:51pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/5 "2025-08-25T19:51:35Z")

</div>

In my [previous](https://openziti.discourse.group/t/failed-to-send-update-router-interfaces-request-to-controller/5037/7) post I wrote that ziti 1.6.7 does not work with ziti controller 1.5.4

The same problem is reported [here](https://openziti.discourse.group/t/zrok-agent-remoting-token-is-malformed/5049).

I have tons of errors on routers while using 1.6.7 with ziti-controller 1.5.4.

I confirm that zrok 1.1.2 work reliably. Zrok 1.1.3 fails in few minutes.

Which version of ziti controller you use to test zrok 1.1.3 ?

These messages we can see in controller’s log (1.5.4) while trying zrok 1.1.3

```auto
{
  "_context": "ch{XXX}->u{classic}->i{XXX/r6MG}",
  "error": "invalid api session id, expected 6946e35b-..., got 0777e9cd-...",
  "file": "github.com/openziti/ziti/controller/handler_edge_ctrl/common.go:78",
  "func": "github.com/openziti/ziti/controller/handler_edge_ctrl.(*baseRequestHandler).returnError",
  "level": "error",
  "msg": "responded with error",
  "operation": "create.circuit",
  "routerId": "XXX",
  "time": "2025-08-25T18:00:43.118Z",
  "token": "eyJh...."
}

```

---

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [September 15, 2025, 2:04pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/6 "2025-09-15T14:04:10Z")

</div>

I have installed 1.6.7 on 2 routers. I confirm that zrok 1.1.3 works without this error.

I think there is a problem connecting zrok 1.1.3 to 1.5.4 routers.

So I need to upgrade all 1.5.4 routers to make zrok 1.1.3 work.

---

<div class="post-metadata">

**Author:** ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)\
**Post date:** [September 15, 2025, 2:10pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/7 "2025-09-15T14:10:08Z")

</div>

> So I need to upgrade all 1.5.4 routers to make zrok 1.1.3 work.

Isn’t that the exact opposite of what you said previously?

ziti v1.6.8 _should_ correct any issues related to zrok and ziti compatibility.

---

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [September 15, 2025, 2:16pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/8 "2025-09-15T14:16:22Z")

</div>

Where you see the opposite?

zrok 1.1.2 does **not have** this problem while connected to ziti-router 1.5.4

zrok 1.1.3 does **have** this problem while connected to ziti-router 1.5.4.

zrok 1.1.3 does **not have** this problem while connected to ziti-router 1.6.7

---

<div class="post-metadata">

**Author:** ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)\
**Post date:** [September 15, 2025, 2:18pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/9 "2025-09-15T14:18:26Z")

</div>

> [@Rantanplan](#):
>
> I have tons of errors on routers while using 1.6.7 with ziti-controller 1.5.4.
> 
> I confirm that zrok 1.1.2 work reliably. Zrok 1.1.3 fails in few minutes.

If this doesn’t contradict the above, then I’m not clearly understanding your version reporting.

Running a different version of the ziti controller and the routers adds a layer of unnecessary complexity.

---

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [September 15, 2025, 2:26pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/10 "2025-09-15T14:26:57Z")

</div>

Yes, It was a problem to connect ziti-router 1.6.7 to ziti-controller 1.5.4. So some additional configuration should be added to make this possible.

Now. I have upgraded ziti-controller 1.5.4 → 1.6.7.

I have only 2 ziti-routers with 1.6.7. So I have connected zrok 1.1.3 to them.

All other routers are under open-ziti 1.5.4. So all clients run zrok 1.1.2. Because zrok 1.1.3 can not work reliably with these routers.

I have understood that it is impossible to run zrok 1.1.3 with open ziti 1.5.4. But zrok 1.1.2 works fine.

---

<div class="post-metadata">

**Author:** ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)\
**Post date:** [September 15, 2025, 2:32pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/11 "2025-09-15T14:32:05Z")

</div>

> [@Rantanplan](#):
>
> I have understood that it is impossible to run zrok 1.1.3 with open ziti 1.5.4. But zrok 1.1.2 works fine.

This is my development environment (ziti 1.5.4 + zrok 1.1.3+), and it works fine. So I’m not sure we’re getting a clear picture of what’s going on.

---

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [September 15, 2025, 2:36pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/12 "2025-09-15T14:36:35Z")

</div>

This is strange. Because it simply does not work for me. I have “invalid api session id” if I connect zrok 1.1.3 to ziti router 1.5.4.

On the other hand, if I connect zrok 1.1.3 to ziti-router 1.6.7 the problem disappears.

---

<div class="post-metadata">

**Author:** ![michael.quigley](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/michael.quigley/32/1123_2.png) [@michael.quigley](https://openziti.discourse.group/u/michael.quigley)\
**Post date:** [September 15, 2025, 2:38pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/13 "2025-09-15T14:38:03Z")

</div>

There’s probably something going on with your ziti configuration that contributes to this issue for you, because those software versions are working fine for me.

Definitely do not mix and match ziti controller and router versions, because that adds yet another variable.

---

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [September 15, 2025, 2:43pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/14 "2025-09-15T14:43:28Z")

</div>

I see. If It works fine for you then the problem is somewhere else.

I can not upgrade all routers and services at the same time. Some services run weeks with no stop.

---

<div class="post-metadata">

**Author:** ![Rantanplan](https://yyz2.discourse-cdn.com/free1/user_avatar/openziti.discourse.group/rantanplan/32/3353_2.png) [@Rantanplan](https://openziti.discourse.group/u/Rantanplan)\
**Post date:** [September 15, 2025, 3:03pm UTC](https://openziti.discourse.group/t/dial-failed-invalid-api-session-id/5056/15 "2025-09-15T15:03:45Z")

</div>

zrok version v1.1.3 [193a0f33]

I have just switched on ziti-routers 1.5.4. Full stop.

```auto
journalctl --since "5 minutes ago" --user -u zrok-agent.service -g error | wc -l
88

{
  "file": "/__w/zrok/zrok/agent/accessPrivate.go:45",
  "func": "github.com/openziti/zrok/agent.(*Agent).AccessPrivate.func1",
  "level": "info",
  "msg": "map[file:/__w/zrok/zrok/endpoints/tcpTunnel/frontend.go:91 func:github.com/openziti/zrok/endpoints/tcpTunnel.(*Frontend).accept level:error msg:error dialing 'myTunnel': unable to dial service 'myTunnel' (dial failed: invalid api session id, expected d277cdce-b26b-484c-8c0f-b85b18a7638d, got b04a53f9-272a-4d74-9582-7beb9f1fdf38) time:2025-09-15T17:00:09.121532267+02:00]",
  "time": "2025-09-15T17:00:09.121Z"
}

```

I should add I use single node HA controller 1.6.7
