influxdata/influxdb · error · AuthenticationError
requestor is forbidden from requested resource
Error message
requestor is forbidden from requested resource
What it means
Variant `Forbidden` of `AuthenticationError` in influxdb3_server/src/http.rs. The requestor presented valid credentials but is not permitted to access the requested resource, so the server rejects the call with a forbidden response.
Solutions
- Create a token with the required permissions (e.g. `influxdb3 create token --permissions 'write:db/mydb'`) and use it instead
- Confirm the token's permission set covers the endpoint and database being called
- Point the client at a database the token is actually authorized for
Example fix
// before: read-only token used for writes // after: issue a token with write permission influxdb3 create token --permissions 'write:db/mydb' --expiry '30d' curl -H 'Authorization: Bearer <new_token>' -X POST 'host/api/v3/write?db=mydb' --data 'm v=1'
Defensive patterns
Strategy: validation
Validate before calling
// Verify token permissions cover the target before calling
async function assertCanWrite(host, token, db) {
const res = await fetch(`${host}/api/v3/write?db=${db}`, {method: 'HEAD', headers: {Authorization: `Bearer ${token}`}});
if (res.status === 403) throw new Error(`token lacks write permission for ${db}`);
} Try / catch
try {
return await api.write(data);
} catch (e) {
if (e.status === 403 || String(e.message).includes('forbidden')) {
throw new PermissionError('token lacks required permissions; issue a token with write scope');
}
throw e;
} Prevention
- Match token permission scope (read/write, database) to the service's actual needs
- Re-issue tokens when service responsibilities change
When it happens
Trigger: Using a token that lacks the required permissions for the target database/resource (e.g. a read-only token against a write endpoint, or a token scoped to another database).
Common situations: Tokens issued for a different environment/instance; least-privilege tokens used by services that later need write access; copying a token from a colleague with narrower permissions; expiring or rotated tokens no longer mapped to sufficient privileges.
Understand the failure class
Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Authorization error
- unauthorized to perform requested action with the token
- action not supported
- arrow error
- authorization failure
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/cc6cf3450e8f3541.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_server/src/http.rs:406
#[error("Current node mode does not use the processing engine")]
NoProcessingEngine,
#[error("invalid request: {0}")]
InvalidRequest(String),
#[error(transparent)]
LegacyWriteParse(#[from] WriteParseError),
}
#[derive(Debug, Error)]
pub(crate) enum AuthenticationError {
#[error("the request was not authenticated")]
Unauthenticated,
#[error(
"Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic"
)]
MalformedRequest,
#[error("requestor is forbidden from requested resource")]
Forbidden,
#[error("to str error: {0}")]
ToStr(#[from] hyper::header::ToStrError),
}
impl IntoResponse for AuthenticationError {
fn into_response(self) -> Response {
let code = match self {
Self::Unauthenticated => StatusCode::UNAUTHORIZED,
Self::MalformedRequest => StatusCode::BAD_REQUEST,
Self::Forbidden => StatusCode::FORBIDDEN,
Self::ToStr(_) => StatusCode::INTERNAL_SERVER_ERROR,
};
ResponseBuilder::new()
.status(code)
.body(bytes_to_response_body(format!(r#"{{"error": "{self}"}}"#)))
.unwrap()View on GitHub (pinned to 06200ef96b)