deepseek-ai/deepseek-harness · error · LlmError
INVALID_CREDENTIAL
INVALID_CREDENTIAL
Error message
this provider's API key is blank; enter it on the Models page, or clear it to probe unauthenticated
What it means
Error "this provider's API key is blank; enter it on the Models page, or clear it to probe unauthenticated" thrown in deepseek-ai/deepseek-harness.
Source
Thrown at packages/llm/llm-pi-ai/src/discovery.ts:175
...contextWindow === undefined ? {} : { contextWindow },
...maxTokens === undefined ? {} : { maxTokens },
})
}
return models
}
/**
* Accept one probe key, or refuse it before the header is built. Without this
* the `fetch` below would throw a ByteString `TypeError` that this function's
* catch reports as `could not reach <url>` — blaming the network for a local,
* deterministic fault.
* @param raw - the key typed into the form or read from storage.
* @returns the trimmed, usable key.
*/
function usableProbeKey(raw: string): string {
const checked = normalizeApiKey(raw)
if (checked.ok) return checked.value
throw new LlmError(
checked.reason === 'empty'
? 'this provider\'s API key is blank; enter it on the Models page, or clear it to probe unauthenticated'
: 'this provider\'s API key contains characters no HTTP header can carry; paste the raw key only',
INVALID_CREDENTIAL_CODE,
)
}
/**
* Interrogate one draft provider endpoint for the models it advertises.
* @param request - the endpoint, protocol, and one-shot credential to use.
* @param storedApiKey - the credential the named route already stored, asked
* for only when the draft carries none and only on the path that reaches the
* network. A configuration surface never holds a stored secret — it edits a
* redacted descriptor — so without this an already-configured route would be
* interrogated unauthenticated and answer 401.
* @returns the advertised models in endpoint order.
* @throws LlmError when the protocol has no readable listing, the endpoint
* refuses or fails the request, or the reply is not a model listing.View on GitHub (pinned to b150a551b8)
Solutions
- Enter the API key on the Models page, or clear it to probe the provider unauthenticated.
When it happens
Trigger: Thrown at packages/llm/llm-pi-ai/src/discovery.ts:175 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
AI-assisted analysis of deepseek-ai/deepseek-harness@b150a551b8 (2026-08-24).
Data as JSON: /api/errors/7b6b5bafdd2b515e.
Report an issue: GitHub.