{"record":{"id":"f321bce02d2d06da","repo":"influxdata/influxdb","slug":"invalid-jwt","errorCode":null,"errorMessage":"invalid JWT","messagePattern":"invalid JWT","errorType":"error_code","errorClass":"AuthenticatorError","httpStatus":null,"severity":"error","filePath":"influxdb3_authz/src/lib.rs","lineNumber":88,"sourceCode":"    Unauthorized,\n\n    #[error(\"resource type not supported, {0}\")]\n    ResourceNotSupported(String),\n}\n\n#[derive(Debug, thiserror::Error)]\npub enum AuthenticatorError {\n    /// Error for token that is present in the request but missing in the catalog\n    #[error(\"token provided is not present in catalog\")]\n    InvalidToken,\n    /// Error for token that has expired\n    #[error(\"token has expired {0}\")]\n    ExpiredToken(String),\n    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)\n    #[error(\"missing token to authenticate\")]\n    MissingToken,\n    /// Error for invalid JWT (bad signature, malformed, etc.)\n    #[error(\"invalid JWT\")]\n    InvalidJwt,\n    /// Error for expired JWT\n    #[error(\"JWT has expired\")]\n    ExpiredJwt,\n}\n\nimpl From<AuthenticatorError> for IoxError {\n    fn from(err: AuthenticatorError) -> Self {\n        match err {\n            AuthenticatorError::InvalidToken => IoxError::NoToken,\n            AuthenticatorError::ExpiredToken(token_expiry_time) => {\n                // there is no mapping to let the caller know about expired token in iox so\n                // we just log it for now (only useful in debugging)\n                debug!(?token_expiry_time, \"supplied token has expired\");\n                IoxError::InvalidToken\n            }\n            AuthenticatorError::MissingToken => IoxError::NoToken,\n            AuthenticatorError::InvalidJwt => IoxError::InvalidToken,","sourceCodeStart":70,"sourceCodeEnd":106,"githubUrl":"https://github.com/influxdata/influxdb/blob/06200ef96ba82c5f6727e5038a83af8e722c6875/influxdb3_authz/src/lib.rs#L70-L106","documentation":"AuthenticatorError::InvalidJwt is returned when the supplied JWT fails validation for reasons other than expiry — bad signature, malformed structure, wrong algorithm, or missing claims. The message is intentionally generic to avoid leaking details to callers.","triggerScenarios":"Presenting a JWT signed by a key the server does not trust; corrupted or truncated JWT strings; JWTs issued for a different audience/issuer than this InfluxDB instance expects.","commonSituations":"Mixing up token types (opaque catalog token vs JWT); clock/key rotation on the identity provider; hand-editing or mis-copying a JWT (base64 segments split incorrectly).","solutions":["Re-obtain a JWT from the correct issuer/signing key configured for this server","Verify the server's trusted issuer/key configuration matches your provider","Ensure the full JWT (all three dot-separated segments) is transmitted intact"],"exampleFix":"// before: truncated jwt\nAuthorization: Bearer eyJhbGciOi...\n// after: full jwt from provider\nAuthorization: Bearer eyJhbGciOiJIUzI1NiIs...eyJzdWIi...SflKxwRJSMeK","handlingStrategy":"validation","validationCode":"// structural sanity check before sending\nlet parts: Vec<&str> = jwt.split('.').collect();\nif parts.len() != 3 || parts.iter().any(|p| p.is_empty()) {\n    return Err(anyhow!(\"malformed JWT: expected 3 non-empty segments\"));\n}","typeGuard":null,"tryCatchPattern":"match auth_result {\n    Err(AuthenticatorError::InvalidJwt) => {\n        // 401; re-fetch a token from the IdP and retry once\n        jwt = fetch_fresh_jwt();\n        retry_once()\n    }\n    r => r?,\n}","preventionTips":["Transmit the full JWT string with no truncation or whitespace edits","Ensure the IdP signing key/algorithm matches server config","Distinguish token types: don't send opaque catalog tokens where a JWT is expected"],"tags":["authentication","jwt","signature","influxdb3"],"backgroundTag":"invalid-argument-format","analyzedSha":"06200ef96ba82c5f6727e5038a83af8e722c6875","analyzedAt":"2026-09-19T12:55:30.003Z","contentChangedAt":"2026-09-19T12:55:30.003Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}