influxdata/influxdb · error · AuthenticatorError

invalid JWT

Error message

invalid JWT

What it means

AuthenticatorError::InvalidJwt is returned when the supplied JWT fails validation for reasons other than expiry — bad signature, malformed structure, wrong algorithm, or missing claims. The message is intentionally generic to avoid leaking details to callers.

Solutions

  1. Re-obtain a JWT from the correct issuer/signing key configured for this server
  2. Verify the server's trusted issuer/key configuration matches your provider
  3. Ensure the full JWT (all three dot-separated segments) is transmitted intact

Example fix

// before: truncated jwt
Authorization: Bearer eyJhbGciOi...
// after: full jwt from provider
Authorization: Bearer eyJhbGciOiJIUzI1NiIs...eyJzdWIi...SflKxwRJSMeK
Defensive patterns

Strategy: validation

Validate before calling

// structural sanity check before sending
let parts: Vec<&str> = jwt.split('.').collect();
if parts.len() != 3 || parts.iter().any(|p| p.is_empty()) {
    return Err(anyhow!("malformed JWT: expected 3 non-empty segments"));
}

Try / catch

match auth_result {
    Err(AuthenticatorError::InvalidJwt) => {
        // 401; re-fetch a token from the IdP and retry once
        jwt = fetch_fresh_jwt();
        retry_once()
    }
    r => r?,
}

Prevention

When it happens

Trigger: Presenting a JWT signed by a key the server does not trust; corrupted or truncated JWT strings; JWTs issued for a different audience/issuer than this InfluxDB instance expects.

Common situations: Mixing up token types (opaque catalog token vs JWT); clock/key rotation on the identity provider; hand-editing or mis-copying a JWT (base64 segments split incorrectly).

Understand the failure class

Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/f321bce02d2d06da. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/lib.rs:88

    Unauthorized,

    #[error("resource type not supported, {0}")]
    ResourceNotSupported(String),
}

#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
    /// Error for token that is present in the request but missing in the catalog
    #[error("token provided is not present in catalog")]
    InvalidToken,
    /// Error for token that has expired
    #[error("token has expired {0}")]
    ExpiredToken(String),
    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
    #[error("missing token to authenticate")]
    MissingToken,
    /// Error for invalid JWT (bad signature, malformed, etc.)
    #[error("invalid JWT")]
    InvalidJwt,
    /// Error for expired JWT
    #[error("JWT has expired")]
    ExpiredJwt,
}

impl From<AuthenticatorError> for IoxError {
    fn from(err: AuthenticatorError) -> Self {
        match err {
            AuthenticatorError::InvalidToken => IoxError::NoToken,
            AuthenticatorError::ExpiredToken(token_expiry_time) => {
                // there is no mapping to let the caller know about expired token in iox so
                // we just log it for now (only useful in debugging)
                debug!(?token_expiry_time, "supplied token has expired");
                IoxError::InvalidToken
            }
            AuthenticatorError::MissingToken => IoxError::NoToken,
            AuthenticatorError::InvalidJwt => IoxError::InvalidToken,

View on GitHub (pinned to 06200ef96b)