influxdata/influxdb · error · AuthenticatorError

JWT has expired

Error message

JWT has expired

What it means

AuthenticatorError::ExpiredJwt is returned when a JWT is structurally valid and correctly signed but its `exp` claim is in the past. The authenticator distinguishes this from expired catalog tokens (ExpiredToken) and invalid JWTs (InvalidJwt). The request must be retried with a freshly issued JWT.

Solutions

  1. Request a new JWT from the identity provider and retry
  2. Implement automatic refresh before the `exp` claim elapses
  3. Increase JWT lifetime if appropriate for the workload

Example fix

// before: jwt fetched once at startup
let jwt = fetch_jwt();
loop { send_request(&jwt); }
// after: refresh on expiry
loop {
    if jwt.expiring_within(60) { jwt = fetch_jwt(); }
    send_request(&jwt);
}
Defensive patterns

Strategy: retry

Validate before calling

// check exp claim before sending
let exp: i64 = jwt_claims["exp"];
if exp <= Utc::now().timestamp() { jwt = refresh_jwt()?; }

Try / catch

match request() {
    Err(AuthenticatorError::ExpiredJwt) => {
        jwt = refresh_jwt()?;  // re-issue from IdP
        request()              // single retry
    }
    r => r,
}

Prevention

When it happens

Trigger: Using a cached JWT beyond its expiry; long-lived connections that keep sending an initially validated JWT; identity-provider sessions ending while the client keeps the old token.

Common situations: Clients without token refresh logic; SDKs holding a JWT for hours; services that fetch a JWT at boot and never refresh it.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/5e91f986d2258f36. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/lib.rs:91

    ResourceNotSupported(String),
}

#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
    /// Error for token that is present in the request but missing in the catalog
    #[error("token provided is not present in catalog")]
    InvalidToken,
    /// Error for token that has expired
    #[error("token has expired {0}")]
    ExpiredToken(String),
    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
    #[error("missing token to authenticate")]
    MissingToken,
    /// Error for invalid JWT (bad signature, malformed, etc.)
    #[error("invalid JWT")]
    InvalidJwt,
    /// Error for expired JWT
    #[error("JWT has expired")]
    ExpiredJwt,
}

impl From<AuthenticatorError> for IoxError {
    fn from(err: AuthenticatorError) -> Self {
        match err {
            AuthenticatorError::InvalidToken => IoxError::NoToken,
            AuthenticatorError::ExpiredToken(token_expiry_time) => {
                // there is no mapping to let the caller know about expired token in iox so
                // we just log it for now (only useful in debugging)
                debug!(?token_expiry_time, "supplied token has expired");
                IoxError::InvalidToken
            }
            AuthenticatorError::MissingToken => IoxError::NoToken,
            AuthenticatorError::InvalidJwt => IoxError::InvalidToken,
            AuthenticatorError::ExpiredJwt => {
                debug!("JWT has expired");
                IoxError::InvalidToken

View on GitHub (pinned to 06200ef96b)