{"record":{"id":"204b4e6fc76ef56a","repo":"upstash/context7","slug":"session-was-rejected-by-the-server","errorCode":null,"errorMessage":"Session was rejected by the server","messagePattern":"Session was rejected by the server","errorType":"exception","errorClass":"SessionRejectedError","httpStatus":401,"severity":"error","filePath":"packages/cli/src/commands/auth.ts","lineNumber":272,"sourceCode":"\ninterface WhoamiResponse {\n  success: boolean;\n  name: string | null;\n  email: string | null;\n  teamspace: { id: string; name: string } | null;\n}\n\nclass SessionRejectedError extends Error {}\n\nasync function fetchWhoami(accessToken: string): Promise<WhoamiResponse> {\n  const response = await fetch(`${getBaseUrl()}/api/dashboard/whoami`, {\n    headers: {\n      Authorization: `Bearer ${accessToken}`,\n    },\n  });\n\n  if (response.status === 401) {\n    throw new SessionRejectedError(\"Session was rejected by the server\");\n  }\n  if (!response.ok) {\n    throw new Error(\"Failed to fetch user info\");\n  }\n\n  return (await response.json()) as WhoamiResponse;\n}\n","sourceCodeStart":254,"sourceCodeEnd":280,"githubUrl":"https://github.com/upstash/context7/blob/4416fb855b8f752be735e34f943b5d0762701aad/packages/cli/src/commands/auth.ts#L254-L280","documentation":"SessionRejectedError is thrown by fetchWhoami when the dashboard /api/dashboard/whoami endpoint responds with HTTP 401. It means the stored access token is present but the server rejected it, so the CLI cannot identify the current user. It is a distinct class so the whoami command can print a targeted 'log in again' message instead of a generic network failure.","triggerScenarios":"fetchWhoami(accessToken) is called (via whoami) and the response from `${getBaseUrl()}/api/dashboard/whoami` with `Authorization: Bearer ${accessToken}` returns status 401.","commonSituations":"The stored auth token has expired or been revoked server-side; the user logged out or rotated keys in another session; token was minted for a different environment/base URL; system clock skew invalidated the token.","solutions":["Run 'ctx7 logout' then 'ctx7 login' to obtain a fresh access token.","Verify you are pointing at the intended base URL (a stale CONTEXT7 base URL config can invalidate the token).","If re-login fails repeatedly, delete stored credentials/config and authenticate from scratch."],"exampleFix":"// before (stale token in shell env)\nexport CONTEXT7_API_TOKEN=old-expired-token\nctx7 whoami\n\n// after (re-authenticate)\nctx7 logout\nctx7 login\nctx7 whoami","handlingStrategy":"try-catch","validationCode":"// Can't validate token validity locally, but ensure it exists and looks like a token before calling:\nif (!accessToken || accessToken.length < 10) {\n  throw new Error('No stored access token; run login first');\n}","typeGuard":"function isSessionRejected(e: unknown): e is SessionRejectedError {\n  return e instanceof SessionRejectedError;\n}","tryCatchPattern":"try {\n  const whoami = await fetchWhoami(token);\n} catch (e) {\n  if (e instanceof SessionRejectedError) {\n    await reauthenticate(); // logout + login\n  } else {\n    console.error('Transient failure, retry later');\n  }\n}","preventionTips":["Re-authenticate proactively when tokens near expiry.","Keep base-URL config consistent between login and subsequent calls.","Handle 401 centrally by clearing stored credentials and prompting re-login."],"tags":["authentication","http-401","cli","session"],"backgroundTag":"authentication-required","analyzedSha":"4416fb855b8f752be735e34f943b5d0762701aad","analyzedAt":"2026-09-16T20:28:07.148Z","contentChangedAt":"2026-09-16T20:28:07.148Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}