RocketChat/Rocket.Chat · error · Error

error-token-param-not-provided

Error message

error-token-param-not-provided

What it means

Thrown by GET /api/v1/livechat/messages.history/:rid when the token query parameter is entirely absent. This is an explicit hand-rolled guard (the AJV schema isGETLivechatMessagesHistoryRidParams evidently permits an omitted token, so the handler checks it itself). It is a malformed-request error, distinct from 'invalid-token' which means 'token present but unknown'.

Solutions

  1. Always append ?token=<visitorToken> (and use encodeURIComponent) when calling the history endpoint.
  2. Ensure the visitor registration step has completed and the token is available before loading history.
  3. If behind a proxy/CDN, verify query strings survive redirects to the API route.

Example fix

// before (query string never appended)
const res = await fetch(`${baseUrl}/api/v1/livechat/messages.history/${rid}`);

// after (required token param included and encoded)
const res = await fetch(`${baseUrl}/api/v1/livechat/messages.history/${rid}?token=${encodeURIComponent(token)}`);
Defensive patterns

Strategy: validation

Validate before calling

// Build the history URL with required params up front
function historyUrl(baseUrl: string, rid: string, token: string): string {
  if (!token) throw new Error('visitor token missing; register before loading history');
  return `${baseUrl}/api/v1/livechat/messages.history/${encodeURIComponent(rid)}?token=${encodeURIComponent(token)}`;
}

Try / catch

if (isLivechatErrorResponse(body) && body.error === 'error-token-param-not-provided') {
  throw new Error('programmer error: history URL built without token'); // fail loudly, it is a client bug
}

Prevention

When it happens

Trigger: GET /api/v1/livechat/messages.history/<rid> with no ?token= query parameter at all, or a URL where the query string got dropped (unencoded template, trailing fragment, redirect stripping the query).

Common situations: Building the history URL by concatenating path segments only; a reverse proxy or SPA router stripping query strings on redirect; the widget mounting history before the visitor registration completed and the token exists.

Understand the failure class

Background: "missing required argument" and "the following required arguments were not provided": what required-argument errors mean and how to fix them — this error's family across 20 libraries.

Related errors


AI-assisted analysis of RocketChat/Rocket.Chat@b2c16d5842 (2026-08-18). Data as JSON: /api/errors/d9d8a4b2939f5bcc. Report an issue: GitHub.

Appendix: source

Thrown at apps/meteor/server/api/v1/omnichannel/message.ts:205

				});
			}

			return API.v1.failure();
		},
	},
);

API.v1.addRoute(
	'livechat/messages.history/:rid',
	{ validateParams: isGETLivechatMessagesHistoryRidParams },
	{
		async get() {
			const { offset } = await getPaginationItems(this.queryParams);
			const { token } = this.queryParams;
			const { rid } = this.urlParams;

			if (!token) {
				throw new Error('error-token-param-not-provided');
			}

			const guest = await findGuest(token);
			if (!guest) {
				throw new Error('invalid-token');
			}

			const room = await findRoom(token, rid);
			if (!room) {
				throw new Error('invalid-room');
			}

			let ls = undefined;
			if (this.queryParams.ls) {
				ls = new Date(this.queryParams.ls);
			}

			let end = undefined;

View on GitHub (pinned to b2c16d5842)