{"record":{"id":"4c38746cbb92ff2c","repo":"RocketChat/Rocket.Chat","slug":"error-authtoken-param-not-valid","errorCode":"error-authToken-param-not-valid","errorMessage":"The required \"authToken\" header param is missing or invalid.","messagePattern":"The required \"authToken\" header param is missing or invalid\\.","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/push.ts","lineNumber":176,"sourceCode":"\t\t\t\t\trequired: ['success', 'result'],\n\t\t\t\t}),\n\t\t\t\t400: validateBadRequestErrorResponse,\n\t\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t\t403: validateForbiddenErrorResponse,\n\t\t\t},\n\t\t\tbody: isPushTokenPOSTProps,\n\t\t\tauthRequired: true,\n\t\t},\n\t\tasync function action() {\n\t\t\tconst { id, type, value, appName, voipToken } = this.bodyParams;\n\n\t\t\tif (voipToken && !id) {\n\t\t\t\treturn API.v1.failure('voip-tokens-must-specify-device-id');\n\t\t\t}\n\n\t\t\tconst rawToken = this.request.headers.get('x-auth-token');\n\t\t\tif (!rawToken) {\n\t\t\t\tthrow new Meteor.Error('error-authToken-param-not-valid', 'The required \"authToken\" header param is missing or invalid.');\n\t\t\t}\n\t\t\tconst authToken = Accounts._hashLoginToken(rawToken);\n\n\t\t\tconst result = await Push.registerPushToken({\n\t\t\t\t...(id && { _id: id }),\n\t\t\t\ttoken: { [type]: value } as IPushToken['token'],\n\t\t\t\tauthToken,\n\t\t\t\tappName,\n\t\t\t\tuserId: this.userId,\n\t\t\t\t...(voipToken && { voipToken }),\n\t\t\t});\n\n\t\t\treturn API.v1.success({ result: cleanTokenResult(result) });\n\t\t},\n\t)\n\t.delete(\n\t\t'push.token',\n\t\t{","sourceCodeStart":158,"sourceCodeEnd":194,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/server/api/v1/push.ts#L158-L194","documentation":"Thrown by POST /api/v1/push.token when the request reaches the handler without an x-auth-token header. Although the endpoint is authRequired (so you authenticated somehow), this specific handler re-reads the raw login token from the header and hashes it with Accounts._hashLoginToken before registering the device token with the push gateway — if the header is absent (query-param style auth, a proxy stripping it), the hash cannot be computed.","triggerScenarios":"POST /api/v1/push.token with body { type, value, appName } authenticated via userId/authToken query params or a bearer scheme that leaves x-auth-token unset; a reverse proxy or HTTP/2 client lowercasing/dropping custom headers; sending X-User-Id but forgetting X-Auth-Token.","commonSituations":"Mobile SDK code that authenticates REST calls through query params or a session cookie and then calls push.token; curl scripts copied with only the user-id header; corporate proxies stripping non-standard headers.","solutions":["Send both headers on every push.token call: X-User-Id and X-Auth-Token with the raw login token / personal access token","If a proxy sits in front, verify it forwards X-Auth-Token (curl -v through the proxy to confirm)","Check the client isn't switching to an auth mode (cookie/bearer) that drops the header right before this call"],"exampleFix":"// before\nawait fetch(`${url}/api/v1/push.token`, { method: 'POST', body: JSON.stringify({ type: 'apn', value: deviceToken, appName: 'myapp' }) });\n\n// after\nawait fetch(`${url}/api/v1/push.token`, {\n  method: 'POST',\n  headers: { 'X-User-Id': uid, 'X-Auth-Token': authToken, 'Content-Type': 'application/json' },\n  body: JSON.stringify({ type: 'apn', value: deviceToken, appName: 'myapp' }),\n});","handlingStrategy":"validation","validationCode":"if (!headers.has('X-Auth-Token')) throw new Error('push.token requires the X-Auth-Token header');\nawait fetch(`${url}/api/v1/push.token`, {\n  method: 'POST',\n  headers: { ...headers, 'X-User-Id': uid, 'X-Auth-Token': authToken, 'Content-Type': 'application/json' },\n  body: JSON.stringify({ type, value, appName }),\n});","typeGuard":null,"tryCatchPattern":"catch 'error-authToken-param-not-valid' and fail fast with a configuration error pointing at the auth headers — retrying without adding x-auth-token cannot succeed.","preventionTips":["Authenticate all push.* REST calls with X-User-Id + X-Auth-Token headers, not query params or cookies","Add an integration test asserting both headers are present on push.token","If a proxy fronts the server, verify it forwards custom X- headers"],"tags":["push","notifications","auth","headers","mobile"],"backgroundTag":"missing-auth-header","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}