{"record":{"id":"c6b7ef785aa05151","repo":"influxdata/influxdb","slug":"cannot-delete-operator-token","errorCode":null,"errorMessage":"cannot delete operator token","messagePattern":"cannot delete operator token","errorType":"error_code","errorClass":"CatalogError","httpStatus":null,"severity":"error","filePath":"influxdb3_catalog/src/error.rs","lineNumber":326,"sourceCode":"    #[error(\"node '{node_id}' has compact mode and cannot be removed\")]\n    NodeModeNotRemovable { node_id: Arc<str> },\n\n    #[error(\"invalid stop ack for node '{node_id}' (current state: {current_state})\")]\n    InvalidStopAck {\n        node_id: Arc<str>,\n        current_state: &'static str,\n    },\n\n    #[error(\"invalid unregister for node '{node_id}' (current state: {current_state})\")]\n    InvalidUnregister {\n        node_id: Arc<str>,\n        current_state: &'static str,\n    },\n\n    #[error(\"idempotent no-op\")]\n    IdempotentNoOp,\n\n    #[error(\"cannot delete operator token\")]\n    CannotDeleteOperatorToken,\n\n    #[error(\n        \"cannot change the configured generation duration for level {level}; \\\n        attempted to set to {attempted:#} but its already set to {existing:#}\"\n    )]\n    CannotChangeGenerationDuration {\n        level: u8,\n        existing: Duration,\n        attempted: Duration,\n    },\n\n    #[error(\"cannot add column {name} because it already exists with type {existing}\")]\n    DuplicateColumn {\n        name: Arc<str>,\n        existing: InfluxColumnType,\n    },\n","sourceCodeStart":308,"sourceCodeEnd":344,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_catalog/src/error.rs#L308-L344","documentation":"Thrown when an attempt is made to delete the operator token from the catalog. The operator token is the bootstrap/admin credential required to administer the instance, so the catalog permanently protects it from deletion.","triggerScenarios":"Calling the token deletion API (DELETE /api/v3/configure/token or catalog delete_token) with the token name/id of the operator token.","commonSituations":"Token cleanup scripts iterating over all tokens and deleting each; revoked-credential workflows accidentally targeting the admin token; multi-tenant cleanup jobs.","solutions":["Skip the operator token in your deletion loop (filter by token name before calling delete).","Delete only named, non-operator API tokens you created.","If the operator token must be rotated, create a new operator token and follow the documented rotation path instead of deleting it."],"exampleFix":"// before\nfor token in catalog.list_tokens()? {\n    catalog.delete_token(&token.name)?;\n}\n// after\nfor token in catalog.list_tokens()? {\n    if token.name != \"operator\" {\n        catalog.delete_token(&token.name)?;\n    }\n}","handlingStrategy":"validation","validationCode":"if token_name == OPERATOR_TOKEN_NAME {\n    return Err(\"refusing to delete the operator token\".into());\n}","typeGuard":null,"tryCatchPattern":"match result {\n    Err(CatalogError::CannotDeleteOperatorToken) => {\n        log::warn!(\"skipped operator token deletion\");\n    }\n    other => other?,\n}","preventionTips":["Filter out the operator token in bulk-delete loops","Never iterate-and-delete all tokens blindly","Rotate credentials via documented rotation instead of delete"],"tags":["auth","tokens","catalog"],"backgroundTag":"operation-not-supported","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}