VectleSkillsThe token used for the server connection is invalid, please update the credentials.

The token used for the server connection is invalid, please update the credentials.

Export

Explains the SonarQube for Visual Studio 11.0.0 connected-mode bug that shows an invalid-token bar even for valid SonarQube Cloud tokens, and gives the staff-suggested DPAPI credential-store workaround plus a downgrade fallback. Use when the bar appears right after updating to 11.0.0 and re-entering or regenerating the token keeps failing. Not for genuinely expired tokens, VS Code or JetBrains IDEs, SonarQube Server auth problems, or missing Execute Analysis permissions.

The token used for the server connection is invalid, please update the credentials

TL;DR

Switch the extension's credential store to the DPAPI-backed store, then re-enter your SonarQube Cloud access token once. The default credential store is broken in 11.0.0: it fails to load saved credentials and silently swallows every save, so every token looks invalid no matter how many times you regenerate it. This is a confirmed bug under active investigation by SonarSource; the DPAPI switch is a workaround until a patch ships.

The error

The token used for the server connection is invalid, please update the credentials.

Fix

  1. Switch to the DPAPI credential store. In Visual Studio, open the SonarQube for Visual Studio options and change the credentials store from the default to the alternative DPAPI-backed store (this is the store SonarSource staff pointed to in the thread).
   Tools, then Options, then SonarQube for Visual Studio: set the credentials store to DPAPI

Success check: restart Visual Studio and confirm the setting is still on DPAPI.

  1. Re-enter your access token once. Use the token bar or the Edit connection dialog to paste your SonarQube Cloud access token. You do not need to regenerate it; the token that worked under 10.9.0 works here.

Success check: the dialog reports success and connected mode stays enabled for the solution.

  1. Verify in the SonarQube output window (View, then Output, then SonarQube): reopen the solution and confirm the lines about missing credentials no longer appear.

Success check: you see "Package initialized" with no credential errors after opening the solution.

  1. If the DPAPI store is not available to you, downgrade instead: uninstall the 11.0.0 extension, install CONTAINER_IP, and re-enter the token. The reporter confirmed connected mode works again.

Success check: the invalid-token bar no longer appears after the downgrade.

Variant phrasings

The token for the selected connection is invalid.

Seen when selecting the connection in the bind dialog after an apparent successful token update. Same bug, same fix.

The credentials of the connection were not updated: Binding could not be established because Server Connection's Credentials could not be found.

Seen when trying to update credentials through the Edit connection dialog. Same bug, same fix.

System.ArgumentException: Unexpected ICredentialsModel argument

Seen by a second reporter in the same build when selecting the connection. Same bug, same fix.

Log lines: "No credentials for connection" / "Migrating connections from existing bindings was not performed"

These output-window lines confirm the credential store failed to load; they are the diagnostic signature of this bug.

When this applies

  • SonarQube for Visual Studio 11.0.0.x on Windows, connected to SonarQube Cloud
  • The invalid-token bar appears immediately after updating the extension, and things worked before the update
  • Re-entering or regenerating the token does not clear the error
  • The output window shows the connections.json migration skip or "No credentials for connection" lines

When this does not apply

  • The token is genuinely expired or revoked: generate a new one in your SonarQube Cloud account
  • SonarQube for VS Code or the JetBrains plugin: different credential plumbing, different fix
  • SonarQube Server auth failures or proxy/TLS connection errors: those are connection problems, not this credential-store bug
  • The token lacks the Execute Analysis permission: that is a permissions error, not this bug

Compatibility

SonarQube for Visual Studio 11.0.0.17354 on Windows (VS 2026 / VS 2022). Confirmed as a bug by SonarSource staff on Oct 8, 2026 with a fix in progress; check for a patch release after 11.0.0 before treating the DPAPI switch as permanent.

Root cause

In 11.0.0 the default credential store cannot be created at runtime (per SonarSource staff, the backing library fails to load), so the extension never loads saved credentials and every save attempt dies with a swallowed KeyNotFoundException inside the aggregating credentials loader. Because nothing can be loaded or persisted, every token - valid or not - is treated as invalid. The DPAPI store uses a different code path that still works, which is why switching stores fixes it without any token change.

Edge cases

  • Staff asked whether multiple copies of the extension exist under the Visual Studio Extensions folder; the reporter had only one. If you have duplicates, uninstall all of them and install a single clean copy.
  • The DPAPI workaround is Windows-only; DPAPI is a Windows API.
  • Do not delete connections.json by hand: the migration step reads it, and staff may ask for debug logs while the real fix is being built.
  • Generating a fresh token is harmless but does not fix this; the bug is in the credential store, not the token.

Workaround confirmed by the reporter in the public thread: https://community.sonarsource.com/t/unable-to-use-connected-mode-after-update-to-version-11-0-0/189145

Provenance

Resolved from the public thread: https://community.sonarsource.com/t/unable-to-use-connected-mode-after-update-to-version-11-0-0/189145

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 9, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 7, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=The+token+used+for+the+server+connection+is+invalid%2C+please+update+the+credentials.&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.