{"record":{"id":"2ecd4391927d9bef","repo":"influxdata/influxdb","slug":"token-has-expired-0","errorCode":null,"errorMessage":"token has expired {0}","messagePattern":"token has expired (.+?)","errorType":"error_code","errorClass":"AuthenticatorError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/lib.rs","lineNumber":82,"sourceCode":"    Admin,\n}\n\n#[derive(Debug, Clone, thiserror::Error)]\npub enum ResourceAuthorizationError {\n    #[error(\"unauthorized to perform requested action with the token\")]\n    Unauthorized,\n\n    #[error(\"resource type not supported, {0}\")]\n    ResourceNotSupported(String),\n}\n\n#[derive(Debug, thiserror::Error)]\npub enum AuthenticatorError {\n    /// Error for token that is present in the request but missing in the catalog\n    #[error(\"token provided is not present in catalog\")]\n    InvalidToken,\n    /// Error for token that has expired\n    #[error(\"token has expired {0}\")]\n    ExpiredToken(String),\n    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)\n    #[error(\"missing token to authenticate\")]\n    MissingToken,\n    /// Error for invalid JWT (bad signature, malformed, etc.)\n    #[error(\"invalid JWT\")]\n    InvalidJwt,\n    /// Error for expired JWT\n    #[error(\"JWT has expired\")]\n    ExpiredJwt,\n}\n\nimpl From<AuthenticatorError> for IoxError {\n    fn from(err: AuthenticatorError) -> Self {\n        match err {\n            AuthenticatorError::InvalidToken => IoxError::NoToken,\n            AuthenticatorError::ExpiredToken(token_expiry_time) => {\n                // there is no mapping to let the caller know about expired token in iox so","sourceCodeStart":64,"sourceCodeEnd":100,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/lib.rs#L64-L100","documentation":"AuthenticatorError::ExpiredToken is returned when the token exists in the catalog but its expiry timestamp has passed. The message includes the expiry details ({0}). The server treats the credential as no longer trustworthy and rejects the request.","triggerScenarios":"A token with a finite TTL is used after its expiry; long-running processes holding a token reference across the expiry boundary; batch jobs started before token rotation.","commonSituations":"CI pipelines reusing cached tokens past their TTL; scheduled jobs with hardcoded tokens; environments where tokens were created with short expiries for testing.","solutions":["Create a fresh token and update the credential store/secret","Automate token rotation before expiry (watch the expiry timestamp in the error)","Prefer non-expiring or long-lived tokens for long-running services"],"exampleFix":"// before\ntoken = load_token() // expired\nclient = Client::new(url, None, false)?.with_auth_token(token)\n// after: refresh if expired\nif token.is_expired() { token = create_new_token() }\nclient = Client::new(url, None, false)?.with_auth_token(token)","handlingStrategy":"retry","validationCode":"// parse expiry before use\nif token_expiry <= Utc::now() { token = create_new_token()?; }","typeGuard":null,"tryCatchPattern":"match result {\n    Err(AuthenticatorError::ExpiredToken(exp)) => {\n        warn!(\"token expired at {exp}; rotating\");\n        rotate_token_and_retry()\n    }\n    r => r?,\n}","preventionTips":["Track token expiry and rotate before it lapses","Use long-lived tokens for unattended services","Fail jobs fast with a clear 'expired token' check at startup"],"tags":["authentication","token","expired","influxdb3"],"backgroundTag":"jwt-token-expired","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}