gofiber/fiber · error

fiber: keyauth unsupported error token

Error message

fiber: keyauth unsupported error token

What it means

keyauth validates Config.Error against the RFC 6750 Bearer error vocabulary. Only three values are allowed: invalid_request, invalid_token, insufficient_scope (the package constants ErrorInvalidRequest, ErrorInvalidToken, ErrorInsufficientScope). Any other string panics, because the WWW-Authenticate challenge must use the standardized error codes or clients cannot interpret them.

Solutions

  1. Use the package constants: keyauth.ErrorInvalidToken, keyauth.ErrorInvalidRequest, or keyauth.ErrorInsufficientScope.
  2. Leave Error empty if you do not need an RFC 6750 challenge (the middleware works without it).
  3. If the value comes from config, validate it against the three allowed strings at load time.

Example fix

// before
app.Use(keyauth.New(keyauth.Config{
    Validator: v,
    Error:     "invalid-token",
}))

// after
app.Use(keyauth.New(keyauth.Config{
    Validator: v,
    Error:     keyauth.ErrorInvalidToken,
}))
Defensive patterns

Strategy: validation

Validate before calling

var allowedErrors = map[string]struct{}{
    keyauth.ErrorInvalidRequest:    {},
    keyauth.ErrorInvalidToken:      {},
    keyauth.ErrorInsufficientScope: {},
}
if cfg.Error != "" {
    if _, ok := allowedErrors[cfg.Error]; !ok {
        log.Fatalf("unsupported keyauth Error: %q", cfg.Error)
    }
}

Prevention

When it happens

Trigger: Setting Config.Error to a free-form string such as "bad_key", "expired", or a typo like "invalid-token" (hyphen instead of underscore). Also triggered by building the value dynamically and producing an empty-but-non-empty-after-trim result, or a custom code.

Common situations: Hand-writing the error code instead of using the package constants; copy-pasting from an OAuth error table that uses different casing/punctuation; version skew if the constants were renamed and code still hardcodes strings.

Related errors


AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11). Data as JSON: /api/errors/9582c4c437cfda3d. Report an issue: GitHub.

Appendix: source

Thrown at middleware/keyauth/config.go:136

	if cfg.Realm == "" {
		cfg.Realm = ConfigDefault.Realm
	}
	if cfg.SuccessHandler == nil {
		cfg.SuccessHandler = ConfigDefault.SuccessHandler
	}
	if cfg.ErrorHandler == nil {
		cfg.ErrorHandler = ConfigDefault.ErrorHandler
	}

	if len(getAuthSchemes(cfg.Extractor)) == 0 && cfg.Challenge == "" {
		cfg.Challenge = fmt.Sprintf("ApiKey realm=%q", cfg.Realm)
	}

	if cfg.Error != "" {
		switch cfg.Error {
		case ErrorInvalidRequest, ErrorInvalidToken, ErrorInsufficientScope:
		default:
			panic("fiber: keyauth unsupported error token")
		}
	}
	if cfg.ErrorDescription != "" && cfg.Error == "" {
		panic("fiber: keyauth error_description requires error")
	}
	if cfg.ErrorURI != "" {
		if cfg.Error == "" {
			panic("fiber: keyauth error_uri requires error")
		}
		if u, err := url.Parse(cfg.ErrorURI); err != nil || !u.IsAbs() {
			panic("fiber: keyauth error_uri must be absolute")
		}
	}
	if cfg.Error == ErrorInsufficientScope {
		if cfg.Scope == "" {
			panic("fiber: keyauth insufficient_scope requires scope")
		}
		for scope := range strings.SplitSeq(cfg.Scope, " ") {

View on GitHub (pinned to a105acad6c)