influxdata/influxdb · error · AuthenticatorError
JWT has expired
Error message
JWT has expired
What it means
AuthenticatorError::ExpiredJwt is returned when a JWT is structurally valid and correctly signed but its `exp` claim is in the past. The authenticator distinguishes this from expired catalog tokens (ExpiredToken) and invalid JWTs (InvalidJwt). The request must be retried with a freshly issued JWT.
Solutions
- Request a new JWT from the identity provider and retry
- Implement automatic refresh before the `exp` claim elapses
- Increase JWT lifetime if appropriate for the workload
Example fix
// before: jwt fetched once at startup
let jwt = fetch_jwt();
loop { send_request(&jwt); }
// after: refresh on expiry
loop {
if jwt.expiring_within(60) { jwt = fetch_jwt(); }
send_request(&jwt);
} Defensive patterns
Strategy: retry
Validate before calling
// check exp claim before sending
let exp: i64 = jwt_claims["exp"];
if exp <= Utc::now().timestamp() { jwt = refresh_jwt()?; } Try / catch
match request() {
Err(AuthenticatorError::ExpiredJwt) => {
jwt = refresh_jwt()?; // re-issue from IdP
request() // single retry
}
r => r,
} Prevention
- Implement JWT refresh scheduled ahead of the exp claim
- Don't cache JWTs beyond their lifetime in processes or CI caches
- Monitor refresh failures with alerts before expiry causes outages
When it happens
Trigger: Using a cached JWT beyond its expiry; long-lived connections that keep sending an initially validated JWT; identity-provider sessions ending while the client keeps the old token.
Common situations: Clients without token refresh logic; SDKs holding a JWT for hours; services that fetch a JWT at boot and never refresh it.
Related errors
- invalid JWT
- token has expired
- missing token to authenticate
- token provided is not present in catalog
- ' ' is a reserved column
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/5e91f986d2258f36.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/lib.rs:91
ResourceNotSupported(String),
}
#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
/// Error for token that is present in the request but missing in the catalog
#[error("token provided is not present in catalog")]
InvalidToken,
/// Error for token that has expired
#[error("token has expired {0}")]
ExpiredToken(String),
/// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
#[error("missing token to authenticate")]
MissingToken,
/// Error for invalid JWT (bad signature, malformed, etc.)
#[error("invalid JWT")]
InvalidJwt,
/// Error for expired JWT
#[error("JWT has expired")]
ExpiredJwt,
}
impl From<AuthenticatorError> for IoxError {
fn from(err: AuthenticatorError) -> Self {
match err {
AuthenticatorError::InvalidToken => IoxError::NoToken,
AuthenticatorError::ExpiredToken(token_expiry_time) => {
// there is no mapping to let the caller know about expired token in iox so
// we just log it for now (only useful in debugging)
debug!(?token_expiry_time, "supplied token has expired");
IoxError::InvalidToken
}
AuthenticatorError::MissingToken => IoxError::NoToken,
AuthenticatorError::InvalidJwt => IoxError::InvalidToken,
AuthenticatorError::ExpiredJwt => {
debug!("JWT has expired");
IoxError::InvalidTokenView on GitHub (pinned to 06200ef96b)