gofiber/fiber · error
encryption key must be 16, 24, or 32 bytes
Error message
encryption key must be 16, 24, or 32 bytes
What it means
Returned by middleware/encryptcookie.decodeKey when a base64-decoded key is not 16, 24, or 32 bytes (AES-128/192/256 key sizes). It is also panicked from the config default path (utils.go:100) when the package-level key fails validation. The lengths map directly to AES; anything else cannot create a cipher.
Solutions
- Generate a proper key: `openssl rand -base64 32` (32 bytes) and use that as Key.
- Confirm the decoded length is exactly 16, 24, or 32 bytes; the error fires after base64 decode, not on the raw string length.
- Keep the key consistent across all instances sharing encrypted cookies (same size and value).
- If migrating key sizes, decrypt existing cookies with the old key and re-encrypt with the new one.
Example fix
// before Key: "my-secret-password" // not a valid AES key // after // generated once: openssl rand -base64 32 Key: "cGFzc3dvcmRwYXNzd29yZHBhc3N3b3JkcGFzc3dvcmQ=" // base64 of 32 bytes
Defensive patterns
Strategy: validation
Validate before calling
func validEncryptKey(b64 string) error {
b, err := base64.StdEncoding.DecodeString(b64)
if err != nil { return err }
switch len(b) {
case 16, 24, 32: return nil
default: return encryptcookie.ErrInvalidKeyLength
}
} Try / catch
if err := encryptcookie.ValidateKey(key); err != nil {
if errors.Is(err, encryptcookie.ErrInvalidKeyLength) {
// regenerate key with correct length before continuing
}
return err
} Prevention
- Generate keys with `openssl rand -base64 32` and store in a secret manager.
- Validate the key at startup; the default config path panics, so catch config errors early.
- Keep key length and value identical across all instances sharing cookies.
When it happens
Trigger: Setting encryptcookie.Config.Key to a base64 string whose decoded length is not 16/24/32 bytes; using a raw passphrase instead of a key; a key generated for a different AES size; truncation or padding in the base64.
Common situations: Pasting a hex or ASCII password into Key instead of a base64-encoded random key; env var truncated; generating a key with the wrong byte length; rotating from a 16-byte to a 32-byte key but not updating the env on all instances.
Related errors
- failed to base64-decode key
- decode SHA256 password: invalid length
- failed to create AES cipher
- failed to create GCM mode
- failed to decrypt ciphertext
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/d43dbc9255f8b9fc.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/encryptcookie/utils.go:14
package encryptcookie
import (
"crypto/aes"
"crypto/cipher"
"crypto/rand"
"encoding/base64"
"errors"
"fmt"
"slices"
)
var (
ErrInvalidKeyLength = errors.New("encryption key must be 16, 24, or 32 bytes")
ErrInvalidEncryptedValue = errors.New("encrypted value is not valid")
)
// decodeKey decodes the provided base64-encoded key and validates its length.
// It returns the decoded key bytes or an error when invalid.
func decodeKey(key string) ([]byte, error) {
keyDecoded, err := base64.StdEncoding.DecodeString(key)
if err != nil {
return nil, fmt.Errorf("failed to base64-decode key: %w", err)
}
keyLen := len(keyDecoded)
if keyLen != 16 && keyLen != 24 && keyLen != 32 {
return nil, ErrInvalidKeyLength
}
return keyDecoded, nil
}View on GitHub (pinned to a105acad6c)