influxdata/influxdb · error · AuthenticatorError
missing token to authenticate
Error message
missing token to authenticate
What it means
AuthenticatorError::MissingToken is returned when no bearer token was present on the request that requires one. The code comments note this should ideally be enforced at the HTTP/gRPC layer before reaching the authenticator. Reaching it means the request bypassed or slipped past that earlier check.
Solutions
- Provide the token: set the Authorization: Bearer header or the CLI --token/env var
- Check that no proxy or HTTP client config strips the Authorization header
- Update clients after enabling auth on the server
Example fix
// before
let client = Client::new(url, ca_cert, tls_no_verify)?;
// after
let client = Client::new(url, ca_cert, tls_no_verify)?
.with_auth_token(&token); Defensive patterns
Strategy: validation
Validate before calling
if auth_token.is_none() {
return Err(anyhow!("INFLUXDB3_AUTH_TOKEN / --token must be set for authenticated endpoints"));
} Try / catch
// ensure header survives the request chain assert!(request.headers().contains_key(AUTHORIZATION), "Authorization header missing");
Prevention
- Set INFLUXDB3_AUTH_TOKEN or pass --token in scripts
- Check HTTP clients/proxies don't strip Authorization headers (esp. on redirects)
- Update client configs when enabling auth on a server
When it happens
Trigger: Calling an authenticated endpoint without an Authorization header; a client configured with auth_token=None; a proxy or middleware stripping the Authorization header.
Common situations: Forgetting to set INFLUXDB3_AUTH_TOKEN or --token in the CLI; HTTP clients that drop headers on redirects; newly enabled auth on a server previously running without it while clients still send no token.
Understand the failure class
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- token has expired
- token provided is not present in catalog
- Authentication error
- duration not to overflow
- from hex error
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/8ca259e50f50e504.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/lib.rs:85
#[derive(Debug, Clone, thiserror::Error)]
pub enum ResourceAuthorizationError {
#[error("unauthorized to perform requested action with the token")]
Unauthorized,
#[error("resource type not supported, {0}")]
ResourceNotSupported(String),
}
#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
/// Error for token that is present in the request but missing in the catalog
#[error("token provided is not present in catalog")]
InvalidToken,
/// Error for token that has expired
#[error("token has expired {0}")]
ExpiredToken(String),
/// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
#[error("missing token to authenticate")]
MissingToken,
/// Error for invalid JWT (bad signature, malformed, etc.)
#[error("invalid JWT")]
InvalidJwt,
/// Error for expired JWT
#[error("JWT has expired")]
ExpiredJwt,
}
impl From<AuthenticatorError> for IoxError {
fn from(err: AuthenticatorError) -> Self {
match err {
AuthenticatorError::InvalidToken => IoxError::NoToken,
AuthenticatorError::ExpiredToken(token_expiry_time) => {
// there is no mapping to let the caller know about expired token in iox so
// we just log it for now (only useful in debugging)
debug!(?token_expiry_time, "supplied token has expired");
IoxError::InvalidTokenView on GitHub (pinned to 06200ef96b)