influxdata/influxdb · error · AuthenticationError

Authorization header was malformed, the request was not in…

Error message

Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic

What it means

Variant `MalformedRequest` of `AuthenticationError` in influxdb3_server/src/http.rs. The Authorization header was present but did not parse into `<auth-scheme> <token>` with one of the supported schemes: Bearer, Token, or Basic.

Solutions

  1. Format the header exactly as `Authorization: Bearer <token>` (or `Token <token>` / `Basic <base64 user:pass>`)
  2. Ensure only one Authorization header is sent and the scheme name is spelled correctly
  3. If using an SDK, let it build the auth header instead of setting a custom one manually

Example fix

// before
curl -H 'Authorization: apiv3_abc123' host/api/v3/query
// after
curl -H 'Authorization: Bearer apiv3_abc123' host/api/v3/query
Defensive patterns

Strategy: validation

Validate before calling

function validateAuthHeader(value) {
  const m = /^\s*(Bearer|Token|Basic)\s+\S+$/.exec(value);
  if (!m) throw new Error("Authorization must be '<scheme> <token>' with scheme Bearer, Token or Basic");
}

Type guard

const isWellFormedAuth = (v) => typeof v === 'string' && /^(Bearer|Token|Basic)\s+\S+$/.test(v.trim());

Try / catch

try {
  return await api.call(headers);
} catch (e) {
  if (String(e.message).includes('Authorization header was malformed')) {
    throw new ConfigError('use format: Authorization: Bearer <token>');
  }
  throw e;
}

Prevention

When it happens

Trigger: Sending an Authorization header with an unsupported scheme (e.g. `Digest`), no scheme at all (bare token), or extra/malformed structure that hyper's header parsing and the auth-scheme splitter cannot decode.

Common situations: Hand-written curl commands pasting only the raw token without a scheme; clients configured for an unsupported auth style; typos like `authorization: bearer` with wrong casing handled fine but `bearer;token=` styles not; double 'Authorization' headers.

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/a6dfdb73133d639b. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_server/src/http.rs:402

    #[error("Timestamp is out of range")]
    TimestampOutOfRange,

    #[error("Current node mode does not use the processing engine")]
    NoProcessingEngine,

    #[error("invalid request: {0}")]
    InvalidRequest(String),

    #[error(transparent)]
    LegacyWriteParse(#[from] WriteParseError),
}

#[derive(Debug, Error)]
pub(crate) enum AuthenticationError {
    #[error("the request was not authenticated")]
    Unauthenticated,
    #[error(
        "Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic"
    )]
    MalformedRequest,
    #[error("requestor is forbidden from requested resource")]
    Forbidden,
    #[error("to str error: {0}")]
    ToStr(#[from] hyper::header::ToStrError),
}

impl IntoResponse for AuthenticationError {
    fn into_response(self) -> Response {
        let code = match self {
            Self::Unauthenticated => StatusCode::UNAUTHORIZED,
            Self::MalformedRequest => StatusCode::BAD_REQUEST,
            Self::Forbidden => StatusCode::FORBIDDEN,
            Self::ToStr(_) => StatusCode::INTERNAL_SERVER_ERROR,
        };

View on GitHub (pinned to 06200ef96b)