influxdata/influxdb · error · AuthenticationError
Authorization header was malformed, the request was not in…
Error message
Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic
What it means
Variant `MalformedRequest` of `AuthenticationError` in influxdb3_server/src/http.rs. The Authorization header was present but did not parse into `<auth-scheme> <token>` with one of the supported schemes: Bearer, Token, or Basic.
Solutions
- Format the header exactly as `Authorization: Bearer <token>` (or `Token <token>` / `Basic <base64 user:pass>`)
- Ensure only one Authorization header is sent and the scheme name is spelled correctly
- If using an SDK, let it build the auth header instead of setting a custom one manually
Example fix
// before curl -H 'Authorization: apiv3_abc123' host/api/v3/query // after curl -H 'Authorization: Bearer apiv3_abc123' host/api/v3/query
Defensive patterns
Strategy: validation
Validate before calling
function validateAuthHeader(value) {
const m = /^\s*(Bearer|Token|Basic)\s+\S+$/.exec(value);
if (!m) throw new Error("Authorization must be '<scheme> <token>' with scheme Bearer, Token or Basic");
} Type guard
const isWellFormedAuth = (v) => typeof v === 'string' && /^(Bearer|Token|Basic)\s+\S+$/.test(v.trim());
Try / catch
try {
return await api.call(headers);
} catch (e) {
if (String(e.message).includes('Authorization header was malformed')) {
throw new ConfigError('use format: Authorization: Bearer <token>');
}
throw e;
} Prevention
- Always let the SDK build the auth header; never hand-concatenate scheme and token
- Only use supported schemes: Bearer, Token, Basic
When it happens
Trigger: Sending an Authorization header with an unsupported scheme (e.g. `Digest`), no scheme at all (bare token), or extra/malformed structure that hyper's header parsing and the auth-scheme splitter cannot decode.
Common situations: Hand-written curl commands pasting only the raw token without a scheme; clients configured for an unsupported auth style; typos like `authorization: bearer` with wrong casing handled fine but `bearer;token=` styles not; double 'Authorization' headers.
Understand the failure class
Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.
- Parsing and encoding errors: unexpected token, malformed input — why parsers reject input and how to find the real culprit.
Related errors
- the request was not authenticated
- arrow error
- Authentication error
- body content is not valid utf8
- Cannot parse the given human time
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/a6dfdb73133d639b.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_server/src/http.rs:402
#[error("Timestamp is out of range")]
TimestampOutOfRange,
#[error("Current node mode does not use the processing engine")]
NoProcessingEngine,
#[error("invalid request: {0}")]
InvalidRequest(String),
#[error(transparent)]
LegacyWriteParse(#[from] WriteParseError),
}
#[derive(Debug, Error)]
pub(crate) enum AuthenticationError {
#[error("the request was not authenticated")]
Unauthenticated,
#[error(
"Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic"
)]
MalformedRequest,
#[error("requestor is forbidden from requested resource")]
Forbidden,
#[error("to str error: {0}")]
ToStr(#[from] hyper::header::ToStrError),
}
impl IntoResponse for AuthenticationError {
fn into_response(self) -> Response {
let code = match self {
Self::Unauthenticated => StatusCode::UNAUTHORIZED,
Self::MalformedRequest => StatusCode::BAD_REQUEST,
Self::Forbidden => StatusCode::FORBIDDEN,
Self::ToStr(_) => StatusCode::INTERNAL_SERVER_ERROR,
};
View on GitHub (pinned to 06200ef96b)