{"record":{"id":"679d3df39de61279","repo":"tiangolo/fastapi","slug":"x-token-header-invalid","errorCode":null,"errorMessage":"X-Token header invalid","messagePattern":"X-Token header invalid","errorType":"http","errorClass":"HTTPException","httpStatus":400,"severity":"error","filePath":"docs_src/bigger_applications/app_an_py310/dependencies.py","lineNumber":8,"sourceCode":"from typing import Annotated\n\nfrom fastapi import Header, HTTPException\n\n\nasync def get_token_header(x_token: Annotated[str, Header()]):\n    if x_token != \"fake-super-secret-token\":\n        raise HTTPException(status_code=400, detail=\"X-Token header invalid\")\n\n\nasync def get_query_token(token: str):\n    if token != \"jessica\":\n        raise HTTPException(status_code=400, detail=\"No Jessica token provided\")\n","sourceCodeStart":1,"sourceCodeEnd":14,"githubUrl":"https://github.com/tiangolo/fastapi/blob/3e8d1526d83a90aaf7d6eb6dc682bf150f180b25/docs_src/bigger_applications/app_an_py310/dependencies.py#L1-L14","documentation":"Raised (400) by the get_token_header dependency used app-wide on the /items APIRouter in the 'bigger applications' example. Any request to a route mounted under that router must carry X-Token equal to 'fake-super-secret-token', or this dependency short-circuits the request before the route body runs. Because it is declared in router dependencies=[Depends(get_token_header)], it applies to every route in the router uniformly.","triggerScenarios":"Any GET/PUT on /items/... without X-Token: fake-super-secret-token. The dependency is attached at router level, so even read_items and update_item are guarded.","commonSituations":"The token is a different literal than the app_testing example ('fake-super-secret-token' vs 'coneofsilence'), so developers who copy headers between examples get 400. Router-level guards are easy to forget when adding a new client.","solutions":["Send X-Token: fake-super-secret-token for any /items/* request.","Note this token differs from other tutorials' tokens; do not reuse headers across examples.","Extract the expected token to a shared config/secret manager."],"exampleFix":"// before\nGET /items/   (no X-Token)\n// after\nGET /items/   X-Token: fake-super-secret-token","handlingStrategy":"validation","validationCode":"import httpx\nTOKEN = 'fake-super-secret-token'\nresp = httpx.get('http://localhost:8000/items/', headers={'X-Token': TOKEN})","typeGuard":"def is_valid_router_token(value: object) -> bool:\n    return isinstance(value, str) and value == 'fake-super-secret-token'","tryCatchPattern":null,"preventionTips":["Do not reuse tokens across tutorial examples; each has its own literal.","Add the X-Token header in a client middleware covering the whole /items router.","Document the expected token per router in the client config."],"tags":["fastapi","authentication","dependency","header","bigger-applications"],"backgroundTag":null,"analyzedSha":"3e8d1526d83a90aaf7d6eb6dc682bf150f180b25","analyzedAt":"2026-08-11T02:34:52.986Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}