{"record":{"id":"7e6c1084e5c1d720","repo":"influxdata/influxdb","slug":"authentication-error-0","errorCode":null,"errorMessage":"Authentication error: {0}","messagePattern":"Authentication error: (.+?)","errorType":"http","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"influxdb3_server/src/http.rs","lineNumber":370,"sourceCode":"    #[error(transparent)]\n    Catalog(#[from] CatalogError),\n\n    #[error(\"Python plugins not enabled on this server\")]\n    PythonPluginsNotEnabled,\n\n    #[error(\"Plugin error: {0}\")]\n    Plugin(#[from] influxdb3_processing_engine::plugins::PluginError),\n\n    #[error(\"Processing engine error: {0}\")]\n    ProcessingEngine(#[from] influxdb3_processing_engine::manager::ProcessingEngineError),\n\n    #[error(transparent)]\n    Influxdb3TypesHttp(#[from] influxdb3_types::http::Error),\n\n    #[error(\"Authorization error: {0}\")]\n    ResourceAuthorization(#[from] ResourceAuthorizationError),\n\n    #[error(\"Authentication error: {0}\")]\n    Authentication(#[from] AuthenticatorError),\n\n    #[error(\"The following Database does not exist: {0}\")]\n    MissingDb(String),\n\n    #[error(\"The following Database Table does not exist: {0}\")]\n    MissingTable(String),\n\n    #[error(\"Cannot parse the given human time: {0}\")]\n    ParsingHumanTime(#[source] humantime::DurationError),\n\n    #[error(\"Cannot parse the timestamp: {0}\")]\n    ParsingTimestamp(#[from] chrono::ParseError),\n\n    #[error(\"Timestamp is out of range\")]\n    TimestampOutOfRange,\n\n    #[error(\"Current node mode does not use the processing engine\")]","sourceCodeStart":352,"sourceCodeEnd":388,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_server/src/http.rs#L352-L388","documentation":"Wraps `AuthenticatorError` via `#[from]` into the server HTTP error enum. Authentication itself failed: the request could not be tied to a valid identity — missing, malformed, expired, or invalid credentials (token), or the authenticator backend could not validate them. Unlike error 603, identity resolution failed, so authorization was never evaluated.","triggerScenarios":"Sending a request with no `Authorization` header, a malformed bearer token, a revoked/expired token, or hitting an endpoint while the server's auth provider cannot validate the token; also occurs when auth is required server-side but the client sends no credentials.","commonSituations":"Token copy-paste errors (whitespace/truncation), tokens rotated on the server but cached in clients, running the server with auth enabled while local dev scripts omit credentials, tokens deleted after a catalog reset.","solutions":["Check that the request includes a valid `Authorization: Bearer <token>` header.","Re-create the token (`influxdb3 create token`) and replace any expired/revoked value in your client config.","Verify the token against the server's current catalog — a reset or migration can invalidate old tokens.","If auth should be off (local dev), start the server without the auth-enabling flag instead of sending bad credentials."],"exampleFix":"// before\n// curl http://localhost:8181/api/v3/query_sql?db=metrics\n// after\n// curl -H \"Authorization: Bearer $INFLUXDB3_TOKEN\" http://localhost:8181/api/v3/query_sql?db=metrics","handlingStrategy":"try-catch","validationCode":"// Fail fast with a clear message before sending requests\nif (!process.env.INFLUXDB3_TOKEN) {\n  throw new Error('INFLUXDB3_TOKEN is not set; cannot authenticate to InfluxDB 3');\n}","typeGuard":"function hasAuthHeaders(headers) {\n  const h = headers['authorization'] ?? headers['Authorization'];\n  return typeof h === 'string' && /^Bearer\\s+\\S+$/.test(h.trim());\n}","tryCatchPattern":"try {\n  return await api.query(sql);\n} catch (e) {\n  if (/Authentication error:/.test(e.message)) {\n    // refresh token once, then retry\n    const token = await fetchNewToken();\n    return await api.query(sql, { token });\n  }\n  throw e;\n}","preventionTips":["Load tokens from env/secret manager; never hardcode","Refresh or re-mint tokens before expiry in long-running clients","Check for whitespace/newlines when pasting tokens into config","If auth is enabled server-side, ensure every environment's scripts supply credentials"],"tags":["authentication","auth","token","http-api"],"backgroundTag":"authentication-required","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}