gofiber/fiber · error
fiber: keyauth unsupported error token
Error message
fiber: keyauth unsupported error token
What it means
keyauth validates Config.Error against the RFC 6750 Bearer error vocabulary. Only three values are allowed: invalid_request, invalid_token, insufficient_scope (the package constants ErrorInvalidRequest, ErrorInvalidToken, ErrorInsufficientScope). Any other string panics, because the WWW-Authenticate challenge must use the standardized error codes or clients cannot interpret them.
Solutions
- Use the package constants: keyauth.ErrorInvalidToken, keyauth.ErrorInvalidRequest, or keyauth.ErrorInsufficientScope.
- Leave Error empty if you do not need an RFC 6750 challenge (the middleware works without it).
- If the value comes from config, validate it against the three allowed strings at load time.
Example fix
// before
app.Use(keyauth.New(keyauth.Config{
Validator: v,
Error: "invalid-token",
}))
// after
app.Use(keyauth.New(keyauth.Config{
Validator: v,
Error: keyauth.ErrorInvalidToken,
})) Defensive patterns
Strategy: validation
Validate before calling
var allowedErrors = map[string]struct{}{
keyauth.ErrorInvalidRequest: {},
keyauth.ErrorInvalidToken: {},
keyauth.ErrorInsufficientScope: {},
}
if cfg.Error != "" {
if _, ok := allowedErrors[cfg.Error]; !ok {
log.Fatalf("unsupported keyauth Error: %q", cfg.Error)
}
} Prevention
- Always reference the package constants instead of hardcoding the error strings.
- Validate Config.Error against the allowed set at the config loader.
- Leave Error empty unless you specifically need an RFC 6750 challenge.
When it happens
Trigger: Setting Config.Error to a free-form string such as "bad_key", "expired", or a typo like "invalid-token" (hyphen instead of underscore). Also triggered by building the value dynamically and producing an empty-but-non-empty-after-trim result, or a custom code.
Common situations: Hand-writing the error code instead of using the package constants; copy-pasting from an OAuth error table that uses different casing/punctuation; version skew if the constants were renamed and code still hardcodes strings.
Related errors
- fiber: keyauth error_description requires error
- fiber: keyauth error_uri must be absolute
- fiber: keyauth error_uri requires error
- fiber: keyauth insufficient_scope requires scope
- fiber: keyauth scope contains invalid token
AI-assisted analysis of gofiber/fiber@a105acad6c (2026-08-11).
Data as JSON: /api/errors/9582c4c437cfda3d.
Report an issue: GitHub.
Appendix: source
Thrown at middleware/keyauth/config.go:136
if cfg.Realm == "" {
cfg.Realm = ConfigDefault.Realm
}
if cfg.SuccessHandler == nil {
cfg.SuccessHandler = ConfigDefault.SuccessHandler
}
if cfg.ErrorHandler == nil {
cfg.ErrorHandler = ConfigDefault.ErrorHandler
}
if len(getAuthSchemes(cfg.Extractor)) == 0 && cfg.Challenge == "" {
cfg.Challenge = fmt.Sprintf("ApiKey realm=%q", cfg.Realm)
}
if cfg.Error != "" {
switch cfg.Error {
case ErrorInvalidRequest, ErrorInvalidToken, ErrorInsufficientScope:
default:
panic("fiber: keyauth unsupported error token")
}
}
if cfg.ErrorDescription != "" && cfg.Error == "" {
panic("fiber: keyauth error_description requires error")
}
if cfg.ErrorURI != "" {
if cfg.Error == "" {
panic("fiber: keyauth error_uri requires error")
}
if u, err := url.Parse(cfg.ErrorURI); err != nil || !u.IsAbs() {
panic("fiber: keyauth error_uri must be absolute")
}
}
if cfg.Error == ErrorInsufficientScope {
if cfg.Scope == "" {
panic("fiber: keyauth insufficient_scope requires scope")
}
for scope := range strings.SplitSeq(cfg.Scope, " ") {View on GitHub (pinned to a105acad6c)