influxdata/influxdb · error · AuthenticationError

requestor is forbidden from requested resource

Error message

requestor is forbidden from requested resource

What it means

Variant `Forbidden` of `AuthenticationError` in influxdb3_server/src/http.rs. The requestor presented valid credentials but is not permitted to access the requested resource, so the server rejects the call with a forbidden response.

Solutions

  1. Create a token with the required permissions (e.g. `influxdb3 create token --permissions 'write:db/mydb'`) and use it instead
  2. Confirm the token's permission set covers the endpoint and database being called
  3. Point the client at a database the token is actually authorized for

Example fix

// before: read-only token used for writes
// after: issue a token with write permission
influxdb3 create token --permissions 'write:db/mydb' --expiry '30d'
curl -H 'Authorization: Bearer <new_token>' -X POST 'host/api/v3/write?db=mydb' --data 'm v=1'
Defensive patterns

Strategy: validation

Validate before calling

// Verify token permissions cover the target before calling
async function assertCanWrite(host, token, db) {
  const res = await fetch(`${host}/api/v3/write?db=${db}`, {method: 'HEAD', headers: {Authorization: `Bearer ${token}`}});
  if (res.status === 403) throw new Error(`token lacks write permission for ${db}`);
}

Try / catch

try {
  return await api.write(data);
} catch (e) {
  if (e.status === 403 || String(e.message).includes('forbidden')) {
    throw new PermissionError('token lacks required permissions; issue a token with write scope');
  }
  throw e;
}

Prevention

When it happens

Trigger: Using a token that lacks the required permissions for the target database/resource (e.g. a read-only token against a write endpoint, or a token scoped to another database).

Common situations: Tokens issued for a different environment/instance; least-privilege tokens used by services that later need write access; copying a token from a colleague with narrower permissions; expiring or rotated tokens no longer mapped to sufficient privileges.

Understand the failure class

Background: Permission denied / not authorized / 403 Forbidden: access-control rejections when the caller lacks the required role, grant, or ownership — this error's family across 18 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/cc6cf3450e8f3541. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_server/src/http.rs:406

    #[error("Current node mode does not use the processing engine")]
    NoProcessingEngine,

    #[error("invalid request: {0}")]
    InvalidRequest(String),

    #[error(transparent)]
    LegacyWriteParse(#[from] WriteParseError),
}

#[derive(Debug, Error)]
pub(crate) enum AuthenticationError {
    #[error("the request was not authenticated")]
    Unauthenticated,
    #[error(
        "Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic"
    )]
    MalformedRequest,
    #[error("requestor is forbidden from requested resource")]
    Forbidden,
    #[error("to str error: {0}")]
    ToStr(#[from] hyper::header::ToStrError),
}

impl IntoResponse for AuthenticationError {
    fn into_response(self) -> Response {
        let code = match self {
            Self::Unauthenticated => StatusCode::UNAUTHORIZED,
            Self::MalformedRequest => StatusCode::BAD_REQUEST,
            Self::Forbidden => StatusCode::FORBIDDEN,
            Self::ToStr(_) => StatusCode::INTERNAL_SERVER_ERROR,
        };

        ResponseBuilder::new()
            .status(code)
            .body(bytes_to_response_body(format!(r#"{{"error": "{self}"}}"#)))
            .unwrap()

View on GitHub (pinned to 06200ef96b)