# Not authorized from Windows KopiaUI to docker Kopia Server

**URL:** <https://kopia.discourse.group/t/not-authorized-from-windows-kopiaui-to-docker-kopia-server/8962>\
**Category:** Support\
**Created:** [August 2, 2026, 3:38pm UTC](https://kopia.discourse.group/t/not-authorized-from-windows-kopiaui-to-docker-kopia-server/8962 "2026-08-02T15:38:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![cybermaus](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@cybermaus](https://kopia.discourse.group/u/cybermaus)\
**Post date:** [August 2, 2026, 3:38pm UTC](https://kopia.discourse.group/t/not-authorized-from-windows-kopiaui-to-docker-kopia-server/8962/1 "2026-08-02T15:38:13Z")

</div>

So I am a new Kopia user. I installed KopiaUI on windows, and am very happy with the results when connecting to my Synology SAN over SMB. Very low CPU usage, 1%, while my WiFi was saturated at 200Mbps

But I was trying to get this to work with a Kopia repository server on the NAS.

So I setup a docker on my NAS. Also setup a reverse proxy with LetsEncrypt for HTTPS, and in the docker/NAS, setup a local repositury to a shared local volume. So far all of that is working.

When I connect to [https://backup.example.fake:51515](https://backup.example.fake:51515), I get a no security warning, thanks to the LetsEncrypt certificate. And when I logon with the UI user kopia and its password, I get the normal UI in which I setup said local repository

So below image is Kopia running in a docker on the Synology NAS

 ![image](https://global.discourse-cdn.com/free1/uploads/kopia/original/2X/c/cd4f26b2905991fe8c11ced4388dd0d05c4dd162.png)

Next I setup client users from the command line:

![image](https://global.discourse-cdn.com/free1/uploads/kopia/original/2X/1/1fda7732a882415179c5976cc73e4359d95a7f6c.png)

However, when I try to connect with the Windows KopiaUI, and I setup a remote repository connection, I of course used above internal user, but that user gets a authority failure

 ![image](https://global.discourse-cdn.com/free1/uploads/kopia/original/2X/0/0b65df94b7af8d04eb49250c93efea5e1407381c.png)

What am I doing wrong?

Copying the error text here for easier reading

```auto
Connect Error: INTERNAL: internal server error: connect error: error opening 
repository: error connecting to API server: unable to establish session for 
purpose=: error establishing session: unable to initialize session: rpc error: 
code = Unauthenticated desc = unexpected HTTP status code received from server: 
401 (Unauthorized); transport: received unexpected content-type "text/plain; 
charset=utf-8": EOF

```

---

<div class="post-metadata">

**Author:** ![cybermaus](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@cybermaus](https://kopia.discourse.group/u/cybermaus)\
**Post date:** [August 4, 2026, 6:30am UTC](https://kopia.discourse.group/t/not-authorized-from-windows-kopiaui-to-docker-kopia-server/8962/2 "2026-08-04T06:30:25Z")

</div>

Some answers I have found with some digging (thanks u/Floss\_Patrol\_76)

**Self-Signed certificate**

I was unable to point directly, because I could not figure out what TLS fingerprint was used. But just drop in any fake fingerprint, connect, and the error will tell you it cannot connect because it was expecting fingerprint xyz… Doh!

Also, if you open it in a browser, and inspect the certificate, it wills show the fingerprint, be it that you have to remove the semicolons.

**The actual problem**

I was using a reverse proxy that only supports HTTP (the Synology build in NGINX based one) but KopiaUI refuses to fall back to HTTP, demands HTTP2/gRPC for its API connection  
So KopiaUI tries gRPC authentication, which is a HTTP2 related thing, gets a HTTP1.1 response back, and fails.

**The actual solution**

Not sure, NGINX does support gRPC, but Synology does not expose it. Either I load the LetsEncrypt certificates directly into Kopia Server (would be best, but how, and how to auto-renew) or I accept the self-signed fingerprint solution. Doing the latter for now.

---

<div class="post-metadata">

**Author:** ![cybermaus](https://avatars.discourse-cdn.com/v4/letter/c/d2c977/32.png) [@cybermaus](https://kopia.discourse.group/u/cybermaus)\
**Post date:** [August 4, 2026, 6:35am UTC](https://kopia.discourse.group/t/not-authorized-from-windows-kopiaui-to-docker-kopia-server/8962/3 "2026-08-04T06:35:52Z")

</div>

A little sidenote, but further useful tip that I am dropping here so I can find it back myself:

You can exclude Kopia from MS defender and thus save a _LOT_ of CPU. Because most CPU goes into the malware check of all the reads, not in Kopia itself:

> `PS C:\Windows\system32> Add-MpPreference -ExclusionProcess C:\Users\<myuser>\AppData\Local\Programs\KopiaUI\resources\server\kopia.exe`

Also checking back, I see FreeFileSync already does the same trick.

> `PS C:\Windows\system32> (Get-MpPreference).ExclusionProcess`  
> `C:\Program Files\FreeFileSync\Bin\FreeFileSync_*.exe`  
> `C:\Program Files\FreeFileSync\FreeFileSync.exe`  
> `C:\Users\<myuser>\AppData\Local\Programs\KopiaUI\resources\server\kopia.exe`
