SECURITY WARNING: Never run commands you don't understand. Always review code before execution. Use at your own risk.
Elixir New Added 28 August 2026

Phoenix: WebSocket connection rejected by check_origin

Phoenix rejects socket connections whose Origin header is not in the allowed list. Behind a reverse proxy the origin often arrives as the internal hostname unless forwarded headers are honoured.

Quick fix

Read the commands before running them. Anything that restarts a service, deletes data or changes permissions should be tried on a non-production system first.

Quick fix
# config/runtime.exs
config :my_app, MyAppWeb.Endpoint,
  check_origin: ["https://app.example.com", "//*.example.com"]

# Make sure the proxy forwards the scheme and host
# nginx:
#   proxy_set_header Host $host;
#   proxy_set_header X-Forwarded-Proto $scheme;

# and the endpoint trusts them
plug Plug.RewriteOn, [:x_forwarded_proto, :x_forwarded_host]

# check_origin: false disables the protection. Do not ship that.

How to diagnose Elixir errors

Elixir errors are shaped by the actor model: a GenServer.call timeout does not mean the server crashed, it means the server was busy for longer than the caller was willing to wait. The right question is usually "what is that process doing?" rather than "why did the call fail?". Because supervisors restart failed processes automatically, transient errors can also hide in the logs while the system appears healthy.

If the quick fix above does not resolve it, work through these steps. They apply to this whole class of error, not just to this one message, which is usually what saves the time.

  1. Attach to a running node with iex --remsh and inspect the process: Process.info(pid, :message_queue_len). A growing mailbox means the process is the bottleneck.
  2. Use :observer.start() to see the supervision tree, process memory and message queues visually.
  3. Move long-running work out of handle_call. Use handle_cast, a Task, or a dedicated pool so the GenServer stays responsive.
  4. Check restart intensity. A supervisor that exceeds max_restarts takes down its own supervisor, producing a cascade that looks like an unrelated failure at the top.
  5. For compile errors in dependencies, run mix deps.compile --force and check that any required native toolchain (make, gcc, erlang headers) is installed.

Tools worth reaching for

  • :observer.start()
  • iex --remsh
  • Process.info/2
  • mix deps.tree
  • :recon

Authoritative references

Primary documentation for this error, worth reading before applying any fix in production.

hexdocs.pm

Related Elixir errors

See all 9 Elixir errors →

Browse other categories

Something missing or wrong?

This entry is maintained by hand. If the fix is out of date, incomplete, or you have a better one, email a correction and it will be reviewed.