immich-app/immich · error · BadRequestException

API Key not found

Error message

API Key not found

What it means

Raised by ApiKeyService.update when apiKeyRepository.getById(auth.user.id, id) returns nothing — the given API key id does not exist or does not belong to the authenticated user. It is a straightforward existence guard before applying the update; the input at fault is the id path parameter.

Solutions

  1. Verify the API key id and re-fetch the key list (GET /api-keys) to get a valid id
  2. Confirm the authenticated user actually owns the key — ids belonging to other users are never found
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at server/src/services/api-key.service.ts:34 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of immich-app/immich@e55ac299a4 (2026-09-15). Data as JSON: /api/errors/5ef5e836b39dee7a. Report an issue: GitHub.

Appendix: source

Thrown at server/src/services/api-key.service.ts:34

    if (auth.apiKey && !isGranted({ requested: dto.permissions, current: auth.apiKey.permissions })) {
      throw new BadRequestException('Cannot grant permissions you do not have');
    }

    const entity = await this.apiKeyRepository.create({
      key: hashed,
      name: dto.name || 'API Key',
      userId: auth.user.id,
      permissions: dto.permissions,
    });
    const apiKey = this.map(entity);

    return { ...apiKey, secret: token, apiKey };
  }

  async update(auth: AuthDto, id: string, dto: ApiKeyUpdateDto): Promise<ApiKeyResponseDto> {
    const exists = await this.apiKeyRepository.getById(auth.user.id, id);
    if (!exists) {
      throw new BadRequestException('API Key not found');
    }

    if (
      auth.apiKey &&
      dto.permissions &&
      !isGranted({ requested: dto.permissions, current: auth.apiKey.permissions })
    ) {
      throw new BadRequestException('Cannot grant permissions you do not have');
    }

    const key = await this.apiKeyRepository.update(auth.user.id, id, { name: dto.name, permissions: dto.permissions });

    return this.map(key);
  }

  async rotate(auth: AuthDto, id: string): Promise<ApiKeyCreateResponseDto> {
    const existing = await findOrFail(() => this.apiKeyRepository.getById(auth.user.id, id), 'API Key not found');

View on GitHub (pinned to e55ac299a4)