{"record":{"id":"193c61be5761693c","repo":"influxdata/influxdb","slug":"the-request-was-not-authenticated","errorCode":null,"errorMessage":"the request was not authenticated","messagePattern":"the request was not authenticated","errorType":"http","errorClass":"AuthenticationError","httpStatus":401,"severity":"error","filePath":"influxdb3_server/src/http.rs","lineNumber":400,"sourceCode":"    #[error(\"Cannot parse the timestamp: {0}\")]\n    ParsingTimestamp(#[from] chrono::ParseError),\n\n    #[error(\"Timestamp is out of range\")]\n    TimestampOutOfRange,\n\n    #[error(\"Current node mode does not use the processing engine\")]\n    NoProcessingEngine,\n\n    #[error(\"invalid request: {0}\")]\n    InvalidRequest(String),\n\n    #[error(transparent)]\n    LegacyWriteParse(#[from] WriteParseError),\n}\n\n#[derive(Debug, Error)]\npub(crate) enum AuthenticationError {\n    #[error(\"the request was not authenticated\")]\n    Unauthenticated,\n    #[error(\n        \"Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic\"\n    )]\n    MalformedRequest,\n    #[error(\"requestor is forbidden from requested resource\")]\n    Forbidden,\n    #[error(\"to str error: {0}\")]\n    ToStr(#[from] hyper::header::ToStrError),\n}\n\nimpl IntoResponse for AuthenticationError {\n    fn into_response(self) -> Response {\n        let code = match self {\n            Self::Unauthenticated => StatusCode::UNAUTHORIZED,\n            Self::MalformedRequest => StatusCode::BAD_REQUEST,\n            Self::Forbidden => StatusCode::FORBIDDEN,\n            Self::ToStr(_) => StatusCode::INTERNAL_SERVER_ERROR,","sourceCodeStart":382,"sourceCodeEnd":418,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_server/src/http.rs#L382-L418","documentation":"Variant `Unauthenticated` of `AuthenticationError` in influxdb3_server/src/http.rs. It is returned when a request arrives with no credentials at all while the server requires authentication, meaning no token was supplied for a protected resource.","triggerScenarios":"Calling any authenticated HTTP API (query, write, management) without an Authorization header; client has no token configured; token header dropped by an intermediate proxy.","commonSituations":"Fresh installations where auth is enabled but the client was never given a token; curl scripts that omit the header; load balancers stripping Authorization headers; SDK clients constructed without credentials.","solutions":["Add an Authorization header with a valid token: `Authorization: Bearer <AUTH_TOKEN>`","Configure the client SDK with the auth token created at server startup (or via `influxdb3 create token`)","Verify intermediate proxies/gateways are not stripping the Authorization header"],"exampleFix":"// before\ncurl 'host/api/v3/query?db=mydb&q=select+1'\n// after\ncurl -H 'Authorization: Bearer apiv3_xxxxxxxxxxxx' 'host/api/v3/query?db=mydb&q=select+1'","handlingStrategy":"validation","validationCode":"function requireToken(cfg) {\n  if (!cfg.token) throw new Error('auth token required: set Authorization: Bearer <token>');\n}","typeGuard":"function hasToken(cfg) {\n  return typeof cfg?.token === 'string' && cfg.token.length > 0;\n}","tryCatchPattern":"try {\n  return await api.call(req);\n} catch (e) {\n  if (e.status === 401 && String(e.message).includes('not authenticated')) {\n    throw new ConfigError('missing auth token; configure Authorization header');\n  }\n  throw e;\n}","preventionTips":["Store the token in config/env at client construction time and fail fast if absent","Verify proxies do not strip the Authorization header"],"tags":["http","authentication","missing-token","authorization-header"],"backgroundTag":"authentication-required","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}