Mintplex-Labs/anything-llm · error · Error
Could not validate login.
Error message
Could not validate login.
What it means
Generic message thrown by requestToken in the AnythingLLM frontend when POST /api/request-token (username/password, optionally a 2FA code) responds non-2xx. The HTTP status and server message are discarded, so wrong credentials, a missing 2FA code, an unknown user, and a suspended account all surface as the same string.
Solutions
- Re-enter credentials carefully; if 2FA is enabled on the account, make sure the code field carries a current TOTP value.
- Confirm multi-user mode is enabled on the server — single-user instances do not expose /request-token.
- Inspect the Network tab for the real status: 401 bad credentials, 404 endpoint not mounted, 403 suspended account.
- Reset the password (user flow or admin reset) if the password is genuinely lost.
Example fix
// before
if (!res.ok) throw new Error('Could not validate login.');
// after — keep the server's message and status
if (!res.ok) {
const data = await res.json().catch(() => null);
throw new Error(data?.message || `Could not validate login. (${res.status})`);
} Defensive patterns
Strategy: validation
Validate before calling
// run before System.requestToken
function validLoginBody(body) {
return (
typeof body?.username === 'string' && body.username.length > 0 &&
typeof body?.password === 'string' && body.password.length > 0
);
}
if (!validLoginBody(body)) throw new Error('Username and password are required'); Try / catch
const { valid, message } = await System.requestToken(body);
if (!valid) {
// message is 'Could not validate login.' — enrich with 2FA hint if code was absent
showLoginError(body.code ? message : `${message} If 2FA is enabled, enter your code.`);
return;
} Prevention
- Clear old tokens/user objects from localStorage before re-login attempts.
- Include the 2FA code field in the form whenever the account has 2FA enabled.
- Confirm multi-user mode is enabled server-side before building login flows.
When it happens
Trigger: POSTing wrong username or password (401); valid credentials but the account has 2FA enabled and the `code` field is missing or wrong; the endpoint not mounted because multi-user mode is disabled (404); account suspended by an admin (403).
Common situations: Password changed elsewhere while a stale login form was open; 2FA enabled recently and the client still sends no code; server upgraded and the session/token format changed; single-user instance where login does not exist at all.
Related errors
- text
- data.message || "Could not update slash command preset."
- data.message || "Error creating slash command preset."
- Error downloading model
- Error downloading model
AI-assisted analysis of Mintplex-Labs/anything-llm@20f6d3546c (2026-08-18).
Data as JSON: /api/errors/fe0675962b369148.
Report an issue: GitHub.
Appendix: source
Thrown at frontend/src/models/system.js:143
},
checkAuth: async function (currentToken = null) {
const valid = await fetch(`${API_BASE}/system/check-token`, {
headers: baseHeaders(currentToken),
})
.then((res) => res.ok)
.catch(() => false);
window.localStorage.setItem(AUTH_TIMESTAMP, Number(new Date()));
return valid;
},
requestToken: async function (body) {
return await fetch(`${API_BASE}/request-token`, {
method: "POST",
body: JSON.stringify({ ...body }),
})
.then((res) => {
if (!res.ok) throw new Error("Could not validate login.");
return res.json();
})
.then((res) => res)
.catch((e) => {
return { valid: false, message: e.message };
});
},
/**
* Refreshes the user object from the session.
* @returns {Promise<{success: boolean, user: Object | null, message: string | null}>}
*/
refreshUser: () => {
return fetch(`${API_BASE}/system/refresh-user`, {
headers: baseHeaders(),
})
.then((res) => {
if (!res.ok) throw new Error("Could not refresh user.");
return res.json();View on GitHub (pinned to 20f6d3546c)