{"record":{"id":"5ef5e836b39dee7a","repo":"immich-app/immich","slug":"api-key-not-found","errorCode":null,"errorMessage":"API Key not found","messagePattern":"API Key not found","errorType":"exception","errorClass":"BadRequestException","httpStatus":400,"severity":"error","filePath":"server/src/services/api-key.service.ts","lineNumber":34,"sourceCode":"    if (auth.apiKey && !isGranted({ requested: dto.permissions, current: auth.apiKey.permissions })) {\n      throw new BadRequestException('Cannot grant permissions you do not have');\n    }\n\n    const entity = await this.apiKeyRepository.create({\n      key: hashed,\n      name: dto.name || 'API Key',\n      userId: auth.user.id,\n      permissions: dto.permissions,\n    });\n    const apiKey = this.map(entity);\n\n    return { ...apiKey, secret: token, apiKey };\n  }\n\n  async update(auth: AuthDto, id: string, dto: ApiKeyUpdateDto): Promise<ApiKeyResponseDto> {\n    const exists = await this.apiKeyRepository.getById(auth.user.id, id);\n    if (!exists) {\n      throw new BadRequestException('API Key not found');\n    }\n\n    if (\n      auth.apiKey &&\n      dto.permissions &&\n      !isGranted({ requested: dto.permissions, current: auth.apiKey.permissions })\n    ) {\n      throw new BadRequestException('Cannot grant permissions you do not have');\n    }\n\n    const key = await this.apiKeyRepository.update(auth.user.id, id, { name: dto.name, permissions: dto.permissions });\n\n    return this.map(key);\n  }\n\n  async rotate(auth: AuthDto, id: string): Promise<ApiKeyCreateResponseDto> {\n    const existing = await findOrFail(() => this.apiKeyRepository.getById(auth.user.id, id), 'API Key not found');\n","sourceCodeStart":16,"sourceCodeEnd":52,"githubUrl":"https://github.com/immich-app/immich/blob/e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c/server/src/services/api-key.service.ts#L16-L52","documentation":"Raised by ApiKeyService.update when apiKeyRepository.getById(auth.user.id, id) returns nothing — the given API key id does not exist or does not belong to the authenticated user. It is a straightforward existence guard before applying the update; the input at fault is the id path parameter.","triggerScenarios":"Thrown at server/src/services/api-key.service.ts:34 when the library encounters an invalid state.","commonSituations":"See trigger scenarios.","solutions":["Verify the API key id and re-fetch the key list (GET /api-keys) to get a valid id","Confirm the authenticated user actually owns the key — ids belonging to other users are never found"],"exampleFix":null,"handlingStrategy":"validation","validationCode":null,"typeGuard":null,"tryCatchPattern":null,"preventionTips":[],"tags":[],"backgroundTag":null,"analyzedSha":"e55ac299a4ec7cb372e35dbf2c6c05ee9ce77f6c","analyzedAt":"2026-09-15T07:20:19.675Z","contentChangedAt":"2026-09-15T07:20:19.675Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}