immich-app/immich · error · ForbiddenException
Not authenticated with an API Key
Error message
Not authenticated with an API Key
What it means
Raised by ApiKeyService.getMine when auth.apiKey is not set — i.e. the request was authenticated by a session cookie or OAuth token instead of an API key. The endpoint is only meaningful for API-key-authenticated requests (it returns the metadata of the key making the call), so any other auth context is rejected.
Solutions
- Send the X-Api-Key header (or API key bearer token) with the request instead of a session cookie
- If building a UI for the logged-in user, use the regular API key listing endpoint rather than /api-keys/me
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at server/src/services/api-key.service.ts:79 when the library encounters an invalid state.
Common situations: See trigger scenarios.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
AI-assisted analysis of immich-app/immich@e55ac299a4 (2026-09-15).
Data as JSON: /api/errors/3bf4313f20a527c7.
Report an issue: GitHub.
Appendix: source
Thrown at server/src/services/api-key.service.ts:79
const hashed = this.cryptoRepository.hashSha256(token);
const newKey = await this.apiKeyRepository.update(auth.user.id, id, { key: hashed });
const apiKey = this.map(newKey);
return { ...apiKey, secret: token, apiKey };
}
async delete(auth: AuthDto, id: string): Promise<void> {
const exists = await this.apiKeyRepository.getById(auth.user.id, id);
if (!exists) {
throw new BadRequestException('API Key not found');
}
await this.apiKeyRepository.delete(auth.user.id, id);
}
async getMine(auth: AuthDto): Promise<ApiKeyResponseDto> {
if (!auth.apiKey) {
throw new ForbiddenException('Not authenticated with an API Key');
}
const key = await this.apiKeyRepository.getById(auth.user.id, auth.apiKey.id);
if (!key) {
throw new BadRequestException('API Key not found');
}
return this.map(key);
}
async getById(auth: AuthDto, id: string): Promise<ApiKeyResponseDto> {
const key = await this.apiKeyRepository.getById(auth.user.id, id);
if (!key) {
throw new BadRequestException('API Key not found');
}
return this.map(key);
}
View on GitHub (pinned to e55ac299a4)