{"record":{"id":"4ef7cd1da6a9a703","repo":"influxdata/influxdb","slug":"the-caller-does-not-have-permission-to-execute-the-specified","errorCode":null,"errorMessage":"The caller does not have permission to execute the specified operation: {0}","messagePattern":"The caller does not have permission to execute the specified operation: (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"core/influxdb_iox_client/src/client/error.rs","lineNumber":84,"sourceCode":"    #[error(\"The operation was cancelled: {0}\")]\n    Cancelled(ServerError<()>),\n\n    #[error(\"Unknown server error: {0}\")]\n    Unknown(ServerError<()>),\n\n    #[error(\"Client specified an invalid argument: {0}\")]\n    InvalidArgument(Box<ServerError<FieldViolation>>),\n\n    #[error(\"Deadline expired before operation could complete: {0}\")]\n    DeadlineExceeded(ServerError<()>),\n\n    #[error(\"{0}\")]\n    NotFound(Box<ServerError<NotFound>>),\n\n    #[error(\"Some entity that we attempted to create already exists: {0}\")]\n    AlreadyExists(Box<ServerError<AlreadyExists>>),\n\n    #[error(\"The caller does not have permission to execute the specified operation: {0}\")]\n    PermissionDenied(ServerError<()>),\n\n    #[error(\"Some resource has been exhausted: {0}\")]\n    ResourceExhausted(ServerError<()>),\n\n    #[error(\"The system is not in a state required for the operation's execution: {0}\")]\n    FailedPrecondition(Box<ServerError<PreconditionViolation>>),\n\n    #[error(\"The operation was aborted: {0}\")]\n    Aborted(ServerError<()>),\n\n    #[error(\"Operation was attempted past the valid range: {0}\")]\n    OutOfRange(ServerError<()>),\n\n    #[error(\"Operation is not implemented or supported: {0}\")]\n    Unimplemented(ServerError<()>),\n\n    #[error(\"Internal error: {0}\")]","sourceCodeStart":66,"sourceCodeEnd":102,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/core/influxdb_iox_client/src/client/error.rs#L66-L102","documentation":"The `Error::PermissionDenied` variant, wrapping a `ServerError<()>`. Raised when the caller lacks permission to execute the specified operation, mirroring gRPC's PERMISSION_DENIED status. Authentication succeeded (or was not the issue) but authorization failed.","triggerScenarios":"Calling a write/admin API with a token lacking the required permission; reading from a namespace the token is not authorized for; operations on resources owned by another tenant.","commonSituations":"Stale or scoped-down API tokens in production configs, using a read-only token for writes, multi-tenant setups where the resource belongs to a different organization.","solutions":["Check the credentials/token the client is configured with and its granted permissions.","Request or provision a token with the permissions needed for the specific operation.","Confirm you are operating on a resource within your own tenant/organization.","If permissions recently changed, restart/reconfigure the client so the new credentials are loaded."],"exampleFix":"// before\nlet client = Client::new(channel).with_token(read_only_token);\nclient.write(ns, data).await?; // write with read-only token\n// after\nlet client = Client::new(channel).with_token(read_write_token);\nclient.write(ns, data).await?;","handlingStrategy":"try-catch","validationCode":"// verify token scope before calls (pseudo)\nif !token.permissions.contains(Permission::Write(ns)) {\n    return Err(\"token lacks write permission\");\n}","typeGuard":"fn is_permission_denied(e: &Error) -> bool { matches!(e, Error::PermissionDenied(_)) }","tryCatchPattern":"match result {\n    Err(Error::PermissionDenied(_)) => { Err(anyhow!(\"insufficient permissions; check token scopes\")) }\n    other => other,\n}","preventionTips":["Provision tokens with least privilege but including all operations the service performs.","Rotate and verify tokens as part of deployment checks, not at first failure.","Keep tenant/organization context in config explicit and reviewed."],"tags":["grpc","auth","permissions","influxdb"],"backgroundTag":"permission-denied","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}