{"record":{"id":"41e3e679b05f6bf3","repo":"tiangolo/fastapi","slug":"x-token-header-invalid-41e3e6","errorCode":null,"errorMessage":"X-Token header invalid","messagePattern":"X-Token header invalid","errorType":"http","errorClass":"HTTPException","httpStatus":400,"severity":"error","filePath":"docs_src/dependencies/tutorial012_py310.py","lineNumber":6,"sourceCode":"from fastapi import Depends, FastAPI, Header, HTTPException\n\n\nasync def verify_token(x_token: str = Header()):\n    if x_token != \"fake-super-secret-token\":\n        raise HTTPException(status_code=400, detail=\"X-Token header invalid\")\n\n\nasync def verify_key(x_key: str = Header()):\n    if x_key != \"fake-super-secret-key\":\n        raise HTTPException(status_code=400, detail=\"X-Key header invalid\")\n    return x_key\n\n\napp = FastAPI(dependencies=[Depends(verify_token), Depends(verify_key)])\n\n\n@app.get(\"/items/\")\nasync def read_items():\n    return [{\"item\": \"Portal Gun\"}, {\"item\": \"Plumbus\"}]\n\n\n@app.get(\"/users/\")\nasync def read_users():","sourceCodeStart":1,"sourceCodeEnd":24,"githubUrl":"https://github.com/tiangolo/fastapi/blob/3e8d1526d83a90aaf7d6eb6dc682bf150f180b25/docs_src/dependencies/tutorial012_py310.py#L1-L24","documentation":"Identical to error 26 but in the non-Annotated tutorial012_py310.py (uses `x_token: str = Header()` instead of `Annotated[str, Header()]`). Same global dependency verify_token enforces X-Token == 'fake-super-secret-token' on every route, raising HTTPException(400) on mismatch.","triggerScenarios":"Any request without a valid X-Token: fake-super-secret-token header. Missing header -> 422; present-but-wrong -> 400.","commonSituations":"Header-token authentication where the client forgets or misnames the header, or where the secret was rotated on the server only.","solutions":["Send X-Token: fake-super-secret-token on every request.","Verify the header name maps to the parameter (x_token -> 'X-Token').","Move the secret to config/env and share it between server and client."],"exampleFix":"// before\nasync def verify_token(x_token: str = Header()):\n    if x_token != \"fake-super-secret-token\":\n        raise HTTPException(status_code=400, detail=\"X-Token header invalid\")\n// after\nimport os\nEXPECTED = os.environ[\"EXPECTED_X_TOKEN\"]\nasync def verify_token(x_token: str = Header()):\n    if x_token != EXPECTED:\n        raise HTTPException(status_code=400, detail=\"X-Token header invalid\")","handlingStrategy":"validation","validationCode":"headers = {'X-Token': os.environ['X_TOKEN']}\nassert headers['X-Token'] == 'fake-super-secret-token'","typeGuard":"def has_valid_x_token(headers: dict) -> bool:\n    return headers.get('X-Token') == 'fake-super-secret-token'","tryCatchPattern":"resp = requests.get(url, headers=headers)\nif resp.status_code == 400:\n    print('X-Token invalid:', resp.json()['detail'])","preventionTips":["Centralize auth headers in an HTTP client wrapper.","Read the secret from config so server and client agree.","Check header spelling against the parameter name."],"tags":["fastapi","http-400","headers","authentication"],"backgroundTag":null,"analyzedSha":"3e8d1526d83a90aaf7d6eb6dc682bf150f180b25","analyzedAt":"2026-08-11T02:34:52.986Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}