{"record":{"id":"8ca259e50f50e504","repo":"influxdata/influxdb","slug":"missing-token-to-authenticate","errorCode":null,"errorMessage":"missing token to authenticate","messagePattern":"missing token to authenticate","errorType":"error_code","errorClass":"AuthenticatorError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/lib.rs","lineNumber":85,"sourceCode":"#[derive(Debug, Clone, thiserror::Error)]\npub enum ResourceAuthorizationError {\n    #[error(\"unauthorized to perform requested action with the token\")]\n    Unauthorized,\n\n    #[error(\"resource type not supported, {0}\")]\n    ResourceNotSupported(String),\n}\n\n#[derive(Debug, thiserror::Error)]\npub enum AuthenticatorError {\n    /// Error for token that is present in the request but missing in the catalog\n    #[error(\"token provided is not present in catalog\")]\n    InvalidToken,\n    /// Error for token that has expired\n    #[error(\"token has expired {0}\")]\n    ExpiredToken(String),\n    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)\n    #[error(\"missing token to authenticate\")]\n    MissingToken,\n    /// Error for invalid JWT (bad signature, malformed, etc.)\n    #[error(\"invalid JWT\")]\n    InvalidJwt,\n    /// Error for expired JWT\n    #[error(\"JWT has expired\")]\n    ExpiredJwt,\n}\n\nimpl From<AuthenticatorError> for IoxError {\n    fn from(err: AuthenticatorError) -> Self {\n        match err {\n            AuthenticatorError::InvalidToken => IoxError::NoToken,\n            AuthenticatorError::ExpiredToken(token_expiry_time) => {\n                // there is no mapping to let the caller know about expired token in iox so\n                // we just log it for now (only useful in debugging)\n                debug!(?token_expiry_time, \"supplied token has expired\");\n                IoxError::InvalidToken","sourceCodeStart":67,"sourceCodeEnd":103,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/lib.rs#L67-L103","documentation":"AuthenticatorError::MissingToken is returned when no bearer token was present on the request that requires one. The code comments note this should ideally be enforced at the HTTP/gRPC layer before reaching the authenticator. Reaching it means the request bypassed or slipped past that earlier check.","triggerScenarios":"Calling an authenticated endpoint without an Authorization header; a client configured with auth_token=None; a proxy or middleware stripping the Authorization header.","commonSituations":"Forgetting to set INFLUXDB3_AUTH_TOKEN or --token in the CLI; HTTP clients that drop headers on redirects; newly enabled auth on a server previously running without it while clients still send no token.","solutions":["Provide the token: set the Authorization: Bearer header or the CLI --token/env var","Check that no proxy or HTTP client config strips the Authorization header","Update clients after enabling auth on the server"],"exampleFix":"// before\nlet client = Client::new(url, ca_cert, tls_no_verify)?;\n// after\nlet client = Client::new(url, ca_cert, tls_no_verify)?\n    .with_auth_token(&token);","handlingStrategy":"validation","validationCode":"if auth_token.is_none() {\n    return Err(anyhow!(\"INFLUXDB3_AUTH_TOKEN / --token must be set for authenticated endpoints\"));\n}","typeGuard":null,"tryCatchPattern":"// ensure header survives the request chain\nassert!(request.headers().contains_key(AUTHORIZATION), \"Authorization header missing\");","preventionTips":["Set INFLUXDB3_AUTH_TOKEN or pass --token in scripts","Check HTTP clients/proxies don't strip Authorization headers (esp. on redirects)","Update client configs when enabling auth on a server"],"tags":["authentication","token","missing-header","influxdb3"],"backgroundTag":"authentication-required","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}