{"record":{"id":"79b5f1e8ed02fd52","repo":"RocketChat/Rocket.Chat","slug":"error-invalid-user-id","errorCode":"error-invalid-user-id","errorMessage":"Invalid user id","messagePattern":"Invalid user id","errorType":"exception","errorClass":"Meteor.Error","httpStatus":400,"severity":"error","filePath":"apps/meteor/server/api/v1/users.ts","lineNumber":1681,"sourceCode":"\t\t\t\t\t\ttokenExpires: { type: 'string' },\n\t\t\t\t\t\tsuccess: { type: 'boolean', enum: [true] },\n\t\t\t\t\t},\n\t\t\t\t\trequired: ['token', 'tokenExpires', 'success'],\n\t\t\t\t\tadditionalProperties: false,\n\t\t\t\t}),\n\t\t\t\t401: validateUnauthorizedErrorResponse,\n\t\t\t},\n\t\t},\n\t\tasync function action() {\n\t\t\tconst xAuthToken = this.request.headers.get('x-auth-token') as string;\n\n\t\t\tif (!xAuthToken) {\n\t\t\t\tthrow new Meteor.Error('error-parameter-required', 'x-auth-token is required');\n\t\t\t}\n\t\t\tconst hashedToken = Accounts._hashLoginToken(xAuthToken);\n\n\t\t\tif (!(await Users.removeNonPATLoginTokensExcept(this.userId, hashedToken))) {\n\t\t\t\tthrow new Meteor.Error('error-invalid-user-id', 'Invalid user id');\n\t\t\t}\n\n\t\t\tconst me = (await Users.findOneById(this.userId, { projection: { 'services.resume.loginTokens': 1 } })) as Pick<IUser, 'services'>;\n\n\t\t\tvoid notifyOnUserChange({\n\t\t\t\tclientAction: 'updated',\n\t\t\t\tid: this.userId,\n\t\t\t\tdiff: { 'services.resume.loginTokens': me.services?.resume?.loginTokens },\n\t\t\t});\n\n\t\t\tconst token = me.services?.resume?.loginTokens?.find((token) => token.hashedToken === hashedToken);\n\n\t\t\tconst loginExp = settings.get<number>('Accounts_LoginExpiration');\n\n\t\t\tconst tokenExpires = (token && 'when' in token && new Date(token.when.getTime() + getLoginExpirationInMs(loginExp))) || undefined;\n\n\t\t\treturn API.v1.success({\n\t\t\t\ttoken: xAuthToken,","sourceCodeStart":1663,"sourceCodeEnd":1699,"githubUrl":"https://github.com/RocketChat/Rocket.Chat/blob/e4b8178b205510181a96ceefee043d0abcd13e5a/apps/meteor/server/api/v1/users.ts#L1663-L1699","documentation":"Thrown by POST /api/v1/users.removeOtherSessions when Users.removeNonPATLoginTokensExcept(userId, hashedToken) returns falsy — i.e. the supplied x-auth-token does not hash-match any persisted non-PAT login token for the user, so the 'keep this session, revoke the rest' operation cannot proceed. Reported as error-invalid-user-id / 'Invalid user id' even though the real problem is the token.","triggerScenarios":"Passing a personal access token (PAT) value in x-auth-token (PATs live outside services.resume.loginTokens); passing an already-revoked or expired session token; passing a token belonging to another user.","commonSituations":"Automation scripts reusing a PAT for a session-scoped endpoint; stale tokens kept in local storage after a password change (which revokes tokens); mixed-up token/userId pairs in multi-account tooling.","solutions":["Use the authToken from a real login response, not a PAT, for this endpoint","Re-login to obtain a fresh token and retry","Verify the token belongs to x-user-id by calling a cheap authenticated endpoint first","If a PAT-only flow is required, use users.logout with logoutOtherSessions semantics or create a proper session"],"exampleFix":"// before\nawait sdk.post('users.removeOtherSessions', {}, { 'x-auth-token': pat }); // PAT -> always fails\n// after\nconst { data } = await sdk.post('login', { user, password });\nawait sdk.post('users.removeOtherSessions', {}, { 'x-auth-token': data.authToken });","handlingStrategy":"validation","validationCode":"const { data } = await sdk.post('login', { user, password });\nif (!data.authToken) throw new Error('login did not yield a resume token');\nawait sdk.post('users.removeOtherSessions', {}, { 'x-auth-token': data.authToken });","typeGuard":"async function tokenIsLive(token: string, uid: string): Promise<boolean> {\n  const res = await fetch(`${rc}/api/v1/me`, { headers: { 'x-auth-token': token, 'x-user-id': uid } });\n  return res.ok;\n}","tryCatchPattern":"try { await sdk.post('users.removeOtherSessions', {}, h); } catch (e) { if (e.response?.data?.errorType === 'error-invalid-user-id') { await relogin(); await sdk.post('users.removeOtherSessions', {}, freshHeaders); } else throw e; }","preventionTips":["Don't reuse PATs for session endpoints","Refresh tokens after password changes","Pair token with its owning userId"],"tags":["rest-api","auth-token","sessions"],"backgroundTag":"invalid-auth-token","analyzedSha":"e4b8178b205510181a96ceefee043d0abcd13e5a","analyzedAt":"2026-08-18T15:26:39.429Z","contentChangedAt":"2026-08-18T15:26:39.429Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}