influxdata/influxdb · error · AuthenticatorError
invalid JWT
Error message
invalid JWT
What it means
AuthenticatorError::InvalidJwt is returned when the supplied JWT fails validation for reasons other than expiry — bad signature, malformed structure, wrong algorithm, or missing claims. The message is intentionally generic to avoid leaking details to callers.
Solutions
- Re-obtain a JWT from the correct issuer/signing key configured for this server
- Verify the server's trusted issuer/key configuration matches your provider
- Ensure the full JWT (all three dot-separated segments) is transmitted intact
Example fix
// before: truncated jwt Authorization: Bearer eyJhbGciOi... // after: full jwt from provider Authorization: Bearer eyJhbGciOiJIUzI1NiIs...eyJzdWIi...SflKxwRJSMeK
Defensive patterns
Strategy: validation
Validate before calling
// structural sanity check before sending
let parts: Vec<&str> = jwt.split('.').collect();
if parts.len() != 3 || parts.iter().any(|p| p.is_empty()) {
return Err(anyhow!("malformed JWT: expected 3 non-empty segments"));
} Try / catch
match auth_result {
Err(AuthenticatorError::InvalidJwt) => {
// 401; re-fetch a token from the IdP and retry once
jwt = fetch_fresh_jwt();
retry_once()
}
r => r?,
} Prevention
- Transmit the full JWT string with no truncation or whitespace edits
- Ensure the IdP signing key/algorithm matches server config
- Distinguish token types: don't send opaque catalog tokens where a JWT is expected
When it happens
Trigger: Presenting a JWT signed by a key the server does not trust; corrupted or truncated JWT strings; JWTs issued for a different audience/issuer than this InfluxDB instance expects.
Common situations: Mixing up token types (opaque catalog token vs JWT); clock/key rotation on the identity provider; hand-editing or mis-copying a JWT (base64 segments split incorrectly).
Understand the failure class
Background: "Invalid ... format", "must be in format X", "does not look like a ..." — invalid argument format errors across CLI tools and libraries — this error's family across 17 libraries.
Related errors
- JWT has expired
- missing token to authenticate
- token has expired
- token provided is not present in catalog
- ' ' is a reserved column
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/f321bce02d2d06da.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/lib.rs:88
Unauthorized,
#[error("resource type not supported, {0}")]
ResourceNotSupported(String),
}
#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
/// Error for token that is present in the request but missing in the catalog
#[error("token provided is not present in catalog")]
InvalidToken,
/// Error for token that has expired
#[error("token has expired {0}")]
ExpiredToken(String),
/// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
#[error("missing token to authenticate")]
MissingToken,
/// Error for invalid JWT (bad signature, malformed, etc.)
#[error("invalid JWT")]
InvalidJwt,
/// Error for expired JWT
#[error("JWT has expired")]
ExpiredJwt,
}
impl From<AuthenticatorError> for IoxError {
fn from(err: AuthenticatorError) -> Self {
match err {
AuthenticatorError::InvalidToken => IoxError::NoToken,
AuthenticatorError::ExpiredToken(token_expiry_time) => {
// there is no mapping to let the caller know about expired token in iox so
// we just log it for now (only useful in debugging)
debug!(?token_expiry_time, "supplied token has expired");
IoxError::InvalidToken
}
AuthenticatorError::MissingToken => IoxError::NoToken,
AuthenticatorError::InvalidJwt => IoxError::InvalidToken,View on GitHub (pinned to 06200ef96b)