{"record":{"id":"061da1733d18753a","repo":"tiangolo/fastapi","slug":"x-token-header-invalid-061da1","errorCode":null,"errorMessage":"X-Token header invalid","messagePattern":"X-Token header invalid","errorType":"http","errorClass":"HTTPException","httpStatus":400,"severity":"error","filePath":"docs_src/dependencies/tutorial006_an_py310.py","lineNumber":10,"sourceCode":"from typing import Annotated\n\nfrom fastapi import Depends, FastAPI, Header, HTTPException\n\napp = FastAPI()\n\n\nasync def verify_token(x_token: Annotated[str, Header()]):\n    if x_token != \"fake-super-secret-token\":\n        raise HTTPException(status_code=400, detail=\"X-Token header invalid\")\n\n\nasync def verify_key(x_key: Annotated[str, Header()]):\n    if x_key != \"fake-super-secret-key\":\n        raise HTTPException(status_code=400, detail=\"X-Key header invalid\")\n    return x_key\n\n\n@app.get(\"/items/\", dependencies=[Depends(verify_token), Depends(verify_key)])\nasync def read_items():\n    return [{\"item\": \"Foo\"}, {\"item\": \"Bar\"}]\n","sourceCodeStart":1,"sourceCodeEnd":22,"githubUrl":"https://github.com/tiangolo/fastapi/blob/3e8d1526d83a90aaf7d6eb6dc682bf150f180b25/docs_src/dependencies/tutorial006_an_py310.py#L1-L22","documentation":"Raised (400) by the verify_token dependency attached to GET /items/ via dependencies=[Depends(verify_token), Depends(verify_key)]. The X-Token header must equal 'fake-super-secret-token'. This is the Annotated-style dependencies tutorial; the dependency does not return a value (it is a pure guard).","triggerScenarios":"GET /items/ without X-Token: fake-super-secret-token. verify_token runs before verify_key, so a bad token short-circuits before the key check.","commonSituations":"Token drift between client and the hardcoded literal; header stripped by proxy; sending the X-Key correctly but forgetting X-Token.","solutions":["Send X-Token: fake-super-secret-token on GET /items/.","Remember both X-Token and X-Key are required on this route.","Centralize the expected secrets in configuration."],"exampleFix":"// before\nGET /items/\n// after\nGET /items/   X-Token: fake-super-secret-token   X-Key: fake-super-secret-key","handlingStrategy":"validation","validationCode":"import httpx\nTOKEN = 'fake-super-secret-token'\nKEY = 'fake-super-secret-key'\nresp = httpx.get('http://localhost:8000/items/', headers={'X-Token': TOKEN, 'X-Key': KEY})","typeGuard":"def is_valid_token_and_key(token: object, key: object) -> bool:\n    return token == 'fake-super-secret-token' and key == 'fake-super-secret-key'","tryCatchPattern":null,"preventionTips":["Both X-Token and X-Key are required; send them together.","Build headers in one place to avoid partial sends.","Keep expected secrets in config."],"tags":["fastapi","authentication","dependency","header","dependencies-tutorial"],"backgroundTag":null,"analyzedSha":"3e8d1526d83a90aaf7d6eb6dc682bf150f180b25","analyzedAt":"2026-08-11T02:34:52.986Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}