immich-app/immich · error · ForbiddenException

Not authenticated with an API Key

Error message

Not authenticated with an API Key

What it means

Raised by ApiKeyService.getMine when auth.apiKey is not set — i.e. the request was authenticated by a session cookie or OAuth token instead of an API key. The endpoint is only meaningful for API-key-authenticated requests (it returns the metadata of the key making the call), so any other auth context is rejected.

Solutions

  1. Send the X-Api-Key header (or API key bearer token) with the request instead of a session cookie
  2. If building a UI for the logged-in user, use the regular API key listing endpoint rather than /api-keys/me
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at server/src/services/api-key.service.ts:79 when the library encounters an invalid state.

Common situations: See trigger scenarios.

Understand the failure class


AI-assisted analysis of immich-app/immich@e55ac299a4 (2026-09-15). Data as JSON: /api/errors/3bf4313f20a527c7. Report an issue: GitHub.

Appendix: source

Thrown at server/src/services/api-key.service.ts:79

    const hashed = this.cryptoRepository.hashSha256(token);
    const newKey = await this.apiKeyRepository.update(auth.user.id, id, { key: hashed });
    const apiKey = this.map(newKey);

    return { ...apiKey, secret: token, apiKey };
  }

  async delete(auth: AuthDto, id: string): Promise<void> {
    const exists = await this.apiKeyRepository.getById(auth.user.id, id);
    if (!exists) {
      throw new BadRequestException('API Key not found');
    }

    await this.apiKeyRepository.delete(auth.user.id, id);
  }

  async getMine(auth: AuthDto): Promise<ApiKeyResponseDto> {
    if (!auth.apiKey) {
      throw new ForbiddenException('Not authenticated with an API Key');
    }

    const key = await this.apiKeyRepository.getById(auth.user.id, auth.apiKey.id);
    if (!key) {
      throw new BadRequestException('API Key not found');
    }

    return this.map(key);
  }

  async getById(auth: AuthDto, id: string): Promise<ApiKeyResponseDto> {
    const key = await this.apiKeyRepository.getById(auth.user.id, id);
    if (!key) {
      throw new BadRequestException('API Key not found');
    }
    return this.map(key);
  }

View on GitHub (pinned to e55ac299a4)