# supabase link: Authorization failed for the access token and project ref pair

TL;DR: your CLI access token and the project ref you passed do not belong together — the token is stale/revoked, or the ref is for a different project or org than the token can see. Run `supabase login` again to mint a fresh token, copy the project ref from the dashboard URL of the project you actually want, and re-run `supabase link --project-ref [ref]`.

```text
LegacyLinkAuthTokenError: Authorization failed for the access token and project ref pair
```

## Steps

1. Run `supabase login` and complete the browser flow. Expected: login succeeds and a fresh access token is stored.

2. Open the project in the dashboard and copy the project ref from the URL — do not guess it from the project name.

3. Run `supabase link --project-ref [ref]` with that exact ref. Expected: linking succeeds and config.toml records the project.

4. Still failing: check that the logged-in account actually has access to the project (right org, not removed). Tokens cannot see projects they were never granted.

## When this applies

- the exact `Authorization failed for the access token and project ref pair` error on supabase link
- linking after the access token was revoked or the account changed teams
- a ref copied from a different project's dashboard URL

## When it doesn't

- database password failures — those happen after linking succeeds
- `Cannot find project ref` on other commands — the link never completed, fix that
- dashboard access issues in the browser itself

## Compatibility

Supabase CLI supabase login / supabase link; access tokens (sb_token) and project refs. Verified against the kw-login-supabase-cli community skill.

## Variant phrasings

- supabase link authorization failed access token project ref
- supabase LegacyLinkAuthTokenError fix
- supabase link invalid project ref

## Root cause

The CLI validates the token/project-ref pair against the Supabase API at link time. A token minted for account A, or a ref belonging to a project the token cannot access, fails the pair check even though each value looks fine on its own.

## Edge cases

- project refs are not secret but tokens are; never paste the token into the link command output you share
- switching between personal and org accounts needs a fresh `supabase login` each time
- old CLI versions produce less clear variants of this error; upgrade if the message differs