{"record":{"id":"3bf4313f20a527c7","repo":"immich-app/immich","slug":"not-authenticated-with-an-api-key","errorCode":null,"errorMessage":"Not authenticated with an API Key","messagePattern":"Not authenticated with an API Key","errorType":"exception","errorClass":"ForbiddenException","httpStatus":403,"severity":"error","filePath":"server/src/services/api-key.service.ts","lineNumber":79,"sourceCode":"    const hashed = this.cryptoRepository.hashSha256(token);\n    const newKey = await this.apiKeyRepository.update(auth.user.id, id, { key: hashed });\n    const apiKey = this.map(newKey);\n\n    return { ...apiKey, secret: token, apiKey };\n  }\n\n  async delete(auth: AuthDto, id: string): Promise<void> {\n    const exists = await this.apiKeyRepository.getById(auth.user.id, id);\n    if (!exists) {\n      throw new BadRequestException('API Key not found');\n    }\n\n    await this.apiKeyRepository.delete(auth.user.id, id);\n  }\n\n  async getMine(auth: AuthDto): Promise<ApiKeyResponseDto> {\n    if (!auth.apiKey) {\n      throw new ForbiddenException('Not authenticated with an API Key');\n    }\n\n    const key = await this.apiKeyRepository.getById(auth.user.id, auth.apiKey.id);\n    if (!key) {\n      throw new BadRequestException('API Key not found');\n    }\n\n    return this.map(key);\n  }\n\n  async getById(auth: AuthDto, id: string): Promise<ApiKeyResponseDto> {\n    const key = await this.apiKeyRepository.getById(auth.user.id, id);\n    if (!key) {\n      throw new BadRequestException('API Key not found');\n    }\n    return this.map(key);\n  }\n","sourceCodeStart":61,"sourceCodeEnd":97,"githubUrl":"https://github.com/immich-app/immich/blob/e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c/server/src/services/api-key.service.ts#L61-L97","documentation":"Raised by ApiKeyService.getMine when auth.apiKey is not set — i.e. the request was authenticated by a session cookie or OAuth token instead of an API key. The endpoint is only meaningful for API-key-authenticated requests (it returns the metadata of the key making the call), so any other auth context is rejected.","triggerScenarios":"Thrown at server/src/services/api-key.service.ts:79 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Send the X-Api-Key header (or API key bearer token) with the request instead of a session cookie","If building a UI for the logged-in user, use the regular API key listing endpoint rather than /api-keys/me"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}