influxdata/influxdb · error · AuthenticatorError

missing token to authenticate

Error message

missing token to authenticate

What it means

AuthenticatorError::MissingToken is returned when no bearer token was present on the request that requires one. The code comments note this should ideally be enforced at the HTTP/gRPC layer before reaching the authenticator. Reaching it means the request bypassed or slipped past that earlier check.

Solutions

  1. Provide the token: set the Authorization: Bearer header or the CLI --token/env var
  2. Check that no proxy or HTTP client config strips the Authorization header
  3. Update clients after enabling auth on the server

Example fix

// before
let client = Client::new(url, ca_cert, tls_no_verify)?;
// after
let client = Client::new(url, ca_cert, tls_no_verify)?
    .with_auth_token(&token);
Defensive patterns

Strategy: validation

Validate before calling

if auth_token.is_none() {
    return Err(anyhow!("INFLUXDB3_AUTH_TOKEN / --token must be set for authenticated endpoints"));
}

Try / catch

// ensure header survives the request chain
assert!(request.headers().contains_key(AUTHORIZATION), "Authorization header missing");

Prevention

When it happens

Trigger: Calling an authenticated endpoint without an Authorization header; a client configured with auth_token=None; a proxy or middleware stripping the Authorization header.

Common situations: Forgetting to set INFLUXDB3_AUTH_TOKEN or --token in the CLI; HTTP clients that drop headers on redirects; newly enabled auth on a server previously running without it while clients still send no token.

Understand the failure class

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/8ca259e50f50e504. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/lib.rs:85

#[derive(Debug, Clone, thiserror::Error)]
pub enum ResourceAuthorizationError {
    #[error("unauthorized to perform requested action with the token")]
    Unauthorized,

    #[error("resource type not supported, {0}")]
    ResourceNotSupported(String),
}

#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
    /// Error for token that is present in the request but missing in the catalog
    #[error("token provided is not present in catalog")]
    InvalidToken,
    /// Error for token that has expired
    #[error("token has expired {0}")]
    ExpiredToken(String),
    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
    #[error("missing token to authenticate")]
    MissingToken,
    /// Error for invalid JWT (bad signature, malformed, etc.)
    #[error("invalid JWT")]
    InvalidJwt,
    /// Error for expired JWT
    #[error("JWT has expired")]
    ExpiredJwt,
}

impl From<AuthenticatorError> for IoxError {
    fn from(err: AuthenticatorError) -> Self {
        match err {
            AuthenticatorError::InvalidToken => IoxError::NoToken,
            AuthenticatorError::ExpiredToken(token_expiry_time) => {
                // there is no mapping to let the caller know about expired token in iox so
                // we just log it for now (only useful in debugging)
                debug!(?token_expiry_time, "supplied token has expired");
                IoxError::InvalidToken

View on GitHub (pinned to 06200ef96b)