{"record":{"id":"3ee39a66d13f10ed","repo":"influxdata/influxdb","slug":"token-provided-is-not-present-in-catalog","errorCode":null,"errorMessage":"token provided is not present in catalog","messagePattern":"token provided is not present in catalog","errorType":"error_code","errorClass":"AuthenticatorError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/lib.rs","lineNumber":79,"sourceCode":"    Role(role::RoleAction),\n    AdminToken(role::AdminTokenAction),\n    ResourceToken(role::TokenAction),\n    Admin,\n}\n\n#[derive(Debug, Clone, thiserror::Error)]\npub enum ResourceAuthorizationError {\n    #[error(\"unauthorized to perform requested action with the token\")]\n    Unauthorized,\n\n    #[error(\"resource type not supported, {0}\")]\n    ResourceNotSupported(String),\n}\n\n#[derive(Debug, thiserror::Error)]\npub enum AuthenticatorError {\n    /// Error for token that is present in the request but missing in the catalog\n    #[error(\"token provided is not present in catalog\")]\n    InvalidToken,\n    /// Error for token that has expired\n    #[error(\"token has expired {0}\")]\n    ExpiredToken(String),\n    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)\n    #[error(\"missing token to authenticate\")]\n    MissingToken,\n    /// Error for invalid JWT (bad signature, malformed, etc.)\n    #[error(\"invalid JWT\")]\n    InvalidJwt,\n    /// Error for expired JWT\n    #[error(\"JWT has expired\")]\n    ExpiredJwt,\n}\n\nimpl From<AuthenticatorError> for IoxError {\n    fn from(err: AuthenticatorError) -> Self {\n        match err {","sourceCodeStart":61,"sourceCodeEnd":97,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/lib.rs#L61-L97","documentation":"AuthenticatorError::InvalidToken indicates that a bearer token was supplied in the request but no matching token exists in the server's catalog. The server refuses to authenticate the request because the credential is unknown. It is an authentication (who-are-you) failure, not an authorization failure.","triggerScenarios":"Sending an Authorization: Bearer <token> whose value was deleted, rotated, or belongs to a different InfluxDB instance; typoes or truncation when copying the token.","commonSituations":"Tokens regenerated without updating client config; pointing a client at a different environment (staging vs prod) that has different tokens; stale tokens in env vars or CI secrets after a revoke.","solutions":["Generate/re-issue a valid token with `influxdb3 create token` and update the client","Verify the token string is complete and unmodified (no whitespace/truncation)","Confirm the client targets the same instance the token was created on"],"exampleFix":"// before\nexport INFLUXDB3_AUTH_TOKEN=old-revoked-token\n// after\nexport INFLUXDB3_AUTH_TOKEN=$(influxdb3 create token --permission ... )","handlingStrategy":"validation","validationCode":"// check the token exists before calling the API\nassert!(!token.is_empty(), \"no auth token configured\");\n// verify via a cheap authenticated endpoint, e.g. GET /health with auth","typeGuard":null,"tryCatchPattern":"// map to 401 and re-provision\ndef call_with_auth(f):\n    try: return f()\n    except ApiError as e:\n        if 'token provided is not present in catalog' in str(e):\n            token = provision_new_token(); return f()  # retry once with fresh token\n        raise","preventionTips":["Store tokens in one source of truth and update it on rotation","Verify tokens against the target environment (staging vs prod)","Never hand-edit token strings; copy programmatically","Re-provision automatically on this error rather than retrying the same token"],"tags":["authentication","token","influxdb3","invalid-credentials"],"backgroundTag":"missing-credentials","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}