Mintplex-Labs/anything-llm · error · Error

Could not validate login.

Error message

Could not validate login.

What it means

Generic message thrown by requestToken in the AnythingLLM frontend when POST /api/request-token (username/password, optionally a 2FA code) responds non-2xx. The HTTP status and server message are discarded, so wrong credentials, a missing 2FA code, an unknown user, and a suspended account all surface as the same string.

Solutions

  1. Re-enter credentials carefully; if 2FA is enabled on the account, make sure the code field carries a current TOTP value.
  2. Confirm multi-user mode is enabled on the server — single-user instances do not expose /request-token.
  3. Inspect the Network tab for the real status: 401 bad credentials, 404 endpoint not mounted, 403 suspended account.
  4. Reset the password (user flow or admin reset) if the password is genuinely lost.

Example fix

// before
if (!res.ok) throw new Error('Could not validate login.');

// after — keep the server's message and status
if (!res.ok) {
  const data = await res.json().catch(() => null);
  throw new Error(data?.message || `Could not validate login. (${res.status})`);
}
Defensive patterns

Strategy: validation

Validate before calling

// run before System.requestToken
function validLoginBody(body) {
  return (
    typeof body?.username === 'string' && body.username.length > 0 &&
    typeof body?.password === 'string' && body.password.length > 0
  );
}
if (!validLoginBody(body)) throw new Error('Username and password are required');

Try / catch

const { valid, message } = await System.requestToken(body);
if (!valid) {
  // message is 'Could not validate login.' — enrich with 2FA hint if code was absent
  showLoginError(body.code ? message : `${message} If 2FA is enabled, enter your code.`);
  return;
}

Prevention

When it happens

Trigger: POSTing wrong username or password (401); valid credentials but the account has 2FA enabled and the `code` field is missing or wrong; the endpoint not mounted because multi-user mode is disabled (404); account suspended by an admin (403).

Common situations: Password changed elsewhere while a stale login form was open; 2FA enabled recently and the client still sends no code; server upgraded and the session/token format changed; single-user instance where login does not exist at all.

Related errors


AI-assisted analysis of Mintplex-Labs/anything-llm@20f6d3546c (2026-08-18). Data as JSON: /api/errors/fe0675962b369148. Report an issue: GitHub.

Appendix: source

Thrown at frontend/src/models/system.js:143

  },

  checkAuth: async function (currentToken = null) {
    const valid = await fetch(`${API_BASE}/system/check-token`, {
      headers: baseHeaders(currentToken),
    })
      .then((res) => res.ok)
      .catch(() => false);

    window.localStorage.setItem(AUTH_TIMESTAMP, Number(new Date()));
    return valid;
  },
  requestToken: async function (body) {
    return await fetch(`${API_BASE}/request-token`, {
      method: "POST",
      body: JSON.stringify({ ...body }),
    })
      .then((res) => {
        if (!res.ok) throw new Error("Could not validate login.");
        return res.json();
      })
      .then((res) => res)
      .catch((e) => {
        return { valid: false, message: e.message };
      });
  },
  /**
   * Refreshes the user object from the session.
   * @returns {Promise<{success: boolean, user: Object | null, message: string | null}>}
   */
  refreshUser: () => {
    return fetch(`${API_BASE}/system/refresh-user`, {
      headers: baseHeaders(),
    })
      .then((res) => {
        if (!res.ok) throw new Error("Could not refresh user.");
        return res.json();

View on GitHub (pinned to 20f6d3546c)