{"record":{"id":"daf8ba5f816847d3","repo":"moeru-ai/airi","slug":"failed-to-create-token-json-stringify-response","errorCode":null,"errorMessage":"Failed to create token: ${JSON.stringify(response) || 'Unknown error'}","messagePattern":"Failed to create token: (.+?)","errorType":"exception","errorClass":"Error","httpStatus":null,"severity":"error","filePath":"packages/stage-ui/src/libs/providers/providers/aliyun-nls/token.ts","lineNumber":134,"sourceCode":"\nexport async function createToken(accessKeyId: string, accessKeySecret: string, options?: CreateTokenOptions): Promise<{ token: string, expiresAt: number }> {\n  const request = await buildCreateTokenRequest(accessKeyId, accessKeySecret, options)\n  const response = await ofetch<{\n    NlsRequestId: string\n    RequestId: string\n    ErrMsg: string\n    Token: { ExpireTime: number, Id: string, UserId: string }\n  } | {\n    RequestId: string\n    Message: string\n    Code: string\n  }>(request.url, { method: 'POST' })\n\n  if ('Token' in response && typeof response.Token === 'object' && 'Id' in response.Token) {\n    return { token: response.Token.Id, expiresAt: response.Token.ExpireTime * 1000 }\n  }\n\n  throw new Error(`Failed to create token: ${JSON.stringify(response) || 'Unknown error'}`)\n}\n","sourceCodeStart":116,"sourceCodeEnd":136,"githubUrl":"https://github.com/moeru-ai/airi/blob/677329427f32468c74b17f3ec47eeca4e05bec65/packages/stage-ui/src/libs/providers/providers/aliyun-nls/token.ts#L116-L136","documentation":"The Aliyun NLS token endpoint answered, but the response lacked Token.Id, so the code treats the whole envelope as an error and embeds it via JSON.stringify — the thrown message therefore contains the server's own RequestId, Code, and Message. This is a server-side rejection of the credentials or the account, not a network failure.","triggerScenarios":"AccessKey pair valid but the RAM user lacks NLS permissions; AK/SK incorrect or disabled; appKey not created in this NLS project or region; account in arrears.","commonSituations":"RAM user created for the app without attaching an NLS access policy; key rotated but provider settings still hold the old one; using keys from a different Alibaba Cloud account than the NLS project.","solutions":["Read the Code and Message inside the thrown JSON — e.g. InvalidAccessKeyId.NotFound, SignatureDoesNotMatch, NoPermission","Attach an NLS access policy to the RAM user in the Alibaba Cloud console","Re-copy AK, SK, and appKey from the console into provider settings","Check the Alibaba Cloud account for overdue payments"],"exampleFix":"// before\nconst { token } = await createAliyunToken(accessKeyId, accessKeySecret)\n// throws: 'Failed to create token: {RequestId, Code: NoPermission, Message}'\n\n// after\ntry {\n  const { token } = await createAliyunToken(accessKeyId, accessKeySecret)\n}\ncatch (err) {\n  const detail = JSON.parse(err.message.replace(/^Failed to create token: /, ''))\n  if (detail.Code === 'NoPermission')\n    throw new Error('Attach an NLS access policy to this RAM user')\n}","handlingStrategy":"try-catch","validationCode":null,"typeGuard":null,"tryCatchPattern":"try {\n  await createAliyunToken(accessKeyId, accessKeySecret)\n}\ncatch (err) {\n  // The message is JSON.stringify of the server envelope — parse it back\n  // to surface Code/Message instead of showing a raw dump.\n  const envelope = JSON.parse(err.message.replace(/^Failed to create token: /, ''))\n  showCredentialError(envelope.Code, envelope.Message)\n}","preventionTips":["Attach the NLS policy to the RAM user before shipping keys","Smoke-test the AK/SK with the Aliyun CLI on first configuration","Treat any non-Token envelope as a config problem and stop retrying"],"tags":["aliyun","nls","token","permissions","ram"],"backgroundTag":"invalid-api-credentials","analyzedSha":"677329427f32468c74b17f3ec47eeca4e05bec65","analyzedAt":"2026-08-18T17:29:58.153Z","contentChangedAt":"2026-08-18T17:29:58.153Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}