{"record":{"id":"24e53546b7e1d0a8","repo":"toeverything/AFFiNE","slug":"access-token-invalid","errorCode":"ACCESS_TOKEN_INVALID","errorMessage":"ACCESS_TOKEN_INVALID","messagePattern":"ACCESS_TOKEN_INVALID","errorType":"error_code","errorClass":"SessionAccessTokenError","httpStatus":401,"severity":"error","filePath":"packages/backend/server/src/core/auth/access-token.ts","lineNumber":69,"sourceCode":"      const token = signAuthSessionAccessToken(\n        userId,\n        authSessionId,\n        key.id,\n        key.secret,\n        issuedAt,\n        expiresAtSeconds\n      );\n      if ((await this.keys.active()).id === key.id) {\n        return { token, expiresAt };\n      }\n    }\n    throw new AuthSessionTemporarilyUnavailable();\n  }\n\n  async verify(token: string): Promise<AuthSessionPrincipal> {\n    const keyId = authSessionAccessTokenKeyId(token);\n    if (!keyId) {\n      throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');\n    }\n    const key = await this.keys.verify(keyId);\n    if (!key) throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');\n    const verified = verifyAuthSessionAccessToken(\n      token,\n      keyId,\n      key.secret,\n      Math.floor(Date.now() / 1000)\n    );\n    if (verified.status !== 'valid') {\n      throw new SessionAccessTokenError(\n        verified.status === 'expired'\n          ? 'ACCESS_TOKEN_EXPIRED'\n          : 'ACCESS_TOKEN_INVALID'\n      );\n    }\n    const { authSessionId, userId } = verified;\n    if (!authSessionId || !userId) {","sourceCodeStart":51,"sourceCodeEnd":87,"githubUrl":"https://github.com/toeverything/AFFiNE/blob/b4c8548c09da21b2898443559a5b846f0ccf5dd8/packages/backend/server/src/core/auth/access-token.ts#L51-L87","documentation":"SessionAccessTokenError with code ACCESS_TOKEN_INVALID is thrown during verify() when the token's embedded key id cannot be parsed (authSessionAccessTokenKeyId returns falsy), meaning the token is malformed or not a valid auth-session access token.","triggerScenarios":"Thrown at packages/backend/server/src/core/auth/access-token.ts:69 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["The access token is malformed or was tampered with — obtain a fresh token via the sign-in or refresh endpoint.","Check the Authorization header format: 'Bearer <token>' with no extra whitespace or quotes.","Ensure client and server share the same signing key/config; a key rotation invalidates old tokens."],"exampleFix":"headers: { Authorization: `Bearer ${accessToken}` }\n// If you still get ACCESS_TOKEN_INVALID, discard the stored token\n// and sign in again.","handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"b4c8548c09da21b2898443559a5b846f0ccf5dd8","analyzedAt":"2026-08-18T21:16:52.546Z","contentChangedAt":"2026-08-18T21:16:52.546Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}