{"record":{"id":"a6dfdb73133d639b","repo":"influxdata/influxdb","slug":"authorization-header-was-malformed-the-request-was-not-in","errorCode":null,"errorMessage":"Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic","messagePattern":"Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic","errorType":"http","errorClass":"AuthenticationError","httpStatus":400,"severity":"error","filePath":"influxdb3_server/src/http.rs","lineNumber":402,"sourceCode":"\n    #[error(\"Timestamp is out of range\")]\n    TimestampOutOfRange,\n\n    #[error(\"Current node mode does not use the processing engine\")]\n    NoProcessingEngine,\n\n    #[error(\"invalid request: {0}\")]\n    InvalidRequest(String),\n\n    #[error(transparent)]\n    LegacyWriteParse(#[from] WriteParseError),\n}\n\n#[derive(Debug, Error)]\npub(crate) enum AuthenticationError {\n    #[error(\"the request was not authenticated\")]\n    Unauthenticated,\n    #[error(\n        \"Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic\"\n    )]\n    MalformedRequest,\n    #[error(\"requestor is forbidden from requested resource\")]\n    Forbidden,\n    #[error(\"to str error: {0}\")]\n    ToStr(#[from] hyper::header::ToStrError),\n}\n\nimpl IntoResponse for AuthenticationError {\n    fn into_response(self) -> Response {\n        let code = match self {\n            Self::Unauthenticated => StatusCode::UNAUTHORIZED,\n            Self::MalformedRequest => StatusCode::BAD_REQUEST,\n            Self::Forbidden => StatusCode::FORBIDDEN,\n            Self::ToStr(_) => StatusCode::INTERNAL_SERVER_ERROR,\n        };\n","sourceCodeStart":384,"sourceCodeEnd":420,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_server/src/http.rs#L384-L420","documentation":"Variant `MalformedRequest` of `AuthenticationError` in influxdb3_server/src/http.rs. The Authorization header was present but did not parse into `<auth-scheme> <token>` with one of the supported schemes: Bearer, Token, or Basic.","triggerScenarios":"Sending an Authorization header with an unsupported scheme (e.g. `Digest`), no scheme at all (bare token), or extra/malformed structure that hyper's header parsing and the auth-scheme splitter cannot decode.","commonSituations":"Hand-written curl commands pasting only the raw token without a scheme; clients configured for an unsupported auth style; typos like `authorization: bearer` with wrong casing handled fine but `bearer;token=` styles not; double 'Authorization' headers.","solutions":["Format the header exactly as `Authorization: Bearer <token>` (or `Token <token>` / `Basic <base64 user:pass>`)","Ensure only one Authorization header is sent and the scheme name is spelled correctly","If using an SDK, let it build the auth header instead of setting a custom one manually"],"exampleFix":"// before\ncurl -H 'Authorization: apiv3_abc123' host/api/v3/query\n// after\ncurl -H 'Authorization: Bearer apiv3_abc123' host/api/v3/query","handlingStrategy":"validation","validationCode":"function validateAuthHeader(value) {\n  const m = /^\\s*(Bearer|Token|Basic)\\s+\\S+$/.exec(value);\n  if (!m) throw new Error(\"Authorization must be '<scheme> <token>' with scheme Bearer, Token or Basic\");\n}","typeGuard":"const isWellFormedAuth = (v) => typeof v === 'string' && /^(Bearer|Token|Basic)\\s+\\S+$/.test(v.trim());","tryCatchPattern":"try {\n  return await api.call(headers);\n} catch (e) {\n  if (String(e.message).includes('Authorization header was malformed')) {\n    throw new ConfigError('use format: Authorization: Bearer <token>');\n  }\n  throw e;\n}","preventionTips":["Always let the SDK build the auth header; never hand-concatenate scheme and token","Only use supported schemes: Bearer, Token, Basic"],"tags":["http","authentication","authorization-header","malformed-header"],"backgroundTag":"invalid-argument-format","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}