{"record":{"id":"6a9fc9ff3a15d48f","repo":"RocketChat/Rocket.Chat","slug":"error-token-does-not-exists","errorCode":"error-token-does-not-exists","errorMessage":"Token does not exist","messagePattern":"Token does not exist","errorType":"exception","errorClass":"Meteor.Error","httpStatus":null,"severity":"error","filePath":"apps/meteor/imports/personal-access-tokens/server/api/methods/regenerateToken.ts","lineNumber":29,"sourceCode":"\t// eslint-disable-next-line @typescript-eslint/naming-convention\n\tinterface ServerMethods {\n\t\t'personalAccessTokens:regenerateToken'(params: { tokenName: string }): Promise<string>;\n\t}\n}\n\nexport const regeneratePersonalAccessTokenOfUser = async (tokenName: string, userId: string): Promise<string> => {\n\tif (!(await hasPermissionAsync(userId, 'create-personal-access-tokens'))) {\n\t\tthrow new Meteor.Error('not-authorized', 'Not Authorized', {\n\t\t\tmethod: 'personalAccessTokens:regenerateToken',\n\t\t});\n\t}\n\n\tconst tokenExist = await Users.findPersonalAccessTokenByTokenNameAndUserId({\n\t\tuserId,\n\t\ttokenName,\n\t});\n\tif (!tokenExist) {\n\t\tthrow new Meteor.Error('error-token-does-not-exists', 'Token does not exist', {\n\t\t\tmethod: 'personalAccessTokens:regenerateToken',\n\t\t});\n\t}\n\n\tawait removePersonalAccessTokenOfUser(tokenName, userId);\n\n\tconst tokenObject = tokenExist.services?.resume?.loginTokens?.find((token) => isPersonalAccessToken(token) && token.name === tokenName);\n\n\treturn generatePersonalAccessTokenOfUser({\n\t\ttokenName,\n\t\tuserId,\n\t\tbypassTwoFactor: (tokenObject && isPersonalAccessToken(tokenObject) && tokenObject.bypassTwoFactor) || false,\n\t});\n};\n\nMeteor.methods<ServerMethods>({\n\t'personalAccessTokens:regenerateToken': twoFactorRequired(async function ({ tokenName }: { tokenName: string }) {\n\t\tconst uid = Meteor.userId();","sourceCodeStart":11,"sourceCodeEnd":47,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0/apps/meteor/imports/personal-access-tokens/server/api/methods/regenerateToken.ts#L11-L47","documentation":"regeneratePersonalAccessTokenOfUser requires an existing token: Users.findPersonalAccessTokenByTokenNameAndUserId({ userId, tokenName }) must return a record whose name matches, otherwise error-token-does-not-exists is thrown. The existing token's bypassTwoFactwoFactor flag is carried over to the regenerated one.","triggerScenarios":"Calling personalAccessTokens:regenerateToken for a name that was never created, was already removed (including a concurrent remove), or is misspelled/differently cased.","commonSituations":"Rotating a token after someone deleted it, scripts referencing retired token names, name typos.","solutions":["List the user's tokens and confirm the exact name (case-sensitive) before regenerating.","If the token was removed, create it again with personalAccessTokens:generateToken.","Avoid concurrent remove+regenerate races for the same token name."],"exampleFix":"// before\nawait Meteor.callAsync('personalAccessTokens:regenerateToken', { tokenName: 'ci-deploy ' }); // trailing space\n\n// after\nconst exists = await Users.findPersonalAccessTokenByTokenNameAndUserId({ userId: uid, tokenName: 'ci-deploy' });\nif (!exists) throw new Error('token missing: create it first with generateToken');\nawait Meteor.callAsync('personalAccessTokens:regenerateToken', { tokenName: 'ci-deploy' });","handlingStrategy":"validation","validationCode":"const token = await Users.findPersonalAccessTokenByTokenNameAndUserId({ userId, tokenName });\nif (!token) {\n\t// nothing to rotate: create it with generateToken first\n}","typeGuard":null,"tryCatchPattern":"try {\n\tawait Meteor.callAsync('personalAccessTokens:regenerateToken', { tokenName });\n} catch (e: any) {\n\tif (e?.error === 'error-token-does-not-exists') {\n\t\tawait Meteor.callAsync('personalAccessTokens:generateToken', { tokenName, bypassTwoFactor: false });\n\t} else throw e;\n}","preventionTips":["List tokens before offering rotation in the UI","Trim and exact-match token names; they are case-sensitive","Avoid concurrent remove and regenerate on the same name"],"tags":["personal-access-tokens","validation","entity-not-found"],"backgroundTag":"entity-not-found","analyzedSha":"b2c16d5842cbe6b69b59bdf6fc5e5f1afcd1f0b0","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}