{"record":{"id":"bf08cfdd964db909","repo":"gofiber/fiber","slug":"missing-or-invalid-api-key","errorCode":null,"errorMessage":"missing or invalid API Key","messagePattern":"missing or invalid API Key","errorType":"http","errorClass":null,"httpStatus":401,"severity":"warning","filePath":"middleware/keyauth/keyauth.go","lineNumber":26,"sourceCode":"\n\t\"github.com/gofiber/fiber/v3\"\n\t\"github.com/gofiber/fiber/v3/extractors\"\n\t\"github.com/gofiber/fiber/v3/internal/redact\"\n\t\"github.com/gofiber/fiber/v3/middleware/logger\"\n\t\"github.com/gofiber/utils/v2\"\n)\n\n// The contextKey type is unexported to prevent collisions with context keys defined in\n// other packages.\ntype contextKey int\n\n// The keys for the values in context\nconst (\n\ttokenKey contextKey = iota\n)\n\n// ErrMissingOrMalformedAPIKey is returned when the API key is missing or invalid.\nvar ErrMissingOrMalformedAPIKey = errors.New(\"missing or invalid API Key\")\n\nvar registerLogContextTagsOnce sync.Once\n\n// New creates a new middleware handler\nfunc New(config ...Config) fiber.Handler {\n\tregisterLogContextTagsOnce.Do(registerLogContextTags)\n\n\t// Init config\n\tcfg := configDefault(config...)\n\n\t// Determine the auth schemes from the extractor chain.\n\tauthSchemes := getAuthSchemes(cfg.Extractor)\n\n\t// The challenge value only depends on config, so build it once instead of\n\t// re-formatting it on every 401/407 response.\n\tchallengeValue := cfg.Challenge\n\tif len(authSchemes) > 0 {\n\t\tchallenges := make([]string, 0, len(authSchemes))","sourceCodeStart":8,"sourceCodeEnd":44,"githubUrl":"https://github.com/gofiber/fiber/blob/a105acad6c1e4576a77f01e02973f67e962bb58d/middleware/keyauth/keyauth.go#L8-L44","documentation":"Returned by middleware/keyauth when the API key cannot be extracted (the Extractor returns extractors.ErrNotFound), or returned from a custom Config.Validator. It replaces the generic extractor-not-found error with a keyauth-specific message and is delivered via the default ErrorHandler as 401 Unauthorized.","triggerScenarios":"A request to a protected route with no API key in the configured source (default Authorization: Bearer), a malformed key, or a Validator that explicitly returns this error (e.g. expired/revoked key).","commonSituations":"Client forgot the Authorization header; sent the key in the wrong scheme (Basic vs Bearer) or wrong header; a custom extractor pointing at a field the client does not populate; a revoked key whose Validator returns this error.","solutions":["Send the API key in the channel and scheme the extractor expects (default: Authorization: Bearer <key>).","Verify Config.Extractor matches where your client puts the key (header/query/cookie/param).","If keys expire, have the client detect 401 and refresh/re-authenticate.","Set Config.TokenLookup correctly if you customized it."],"exampleFix":"// before: missing or wrong scheme\n// after\nreq.Header.Set(\"Authorization\", \"Bearer \"+apiKey)","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"if errors.Is(err, keyauth.ErrMissingOrMalformedAPIKey) {\n    return c.Status(fiber.StatusUnauthorized).SendString(\"api key required\")\n}","preventionTips":["Send the key in the channel and scheme the extractor expects (default Authorization: Bearer).","Align Config.Extractor / TokenLookup with where the client puts the key.","Have clients detect 401 and refresh credentials."],"tags":["keyauth","auth","security"],"backgroundTag":null,"analyzedSha":"a105acad6c1e4576a77f01e02973f67e962bb58d","analyzedAt":"2026-08-11T17:33:26.942Z","contentChangedAt":null,"schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}