influxdata/influxdb · error · AuthenticationError

the request was not authenticated

Error message

the request was not authenticated

What it means

Variant `Unauthenticated` of `AuthenticationError` in influxdb3_server/src/http.rs. It is returned when a request arrives with no credentials at all while the server requires authentication, meaning no token was supplied for a protected resource.

Solutions

  1. Add an Authorization header with a valid token: `Authorization: Bearer <AUTH_TOKEN>`
  2. Configure the client SDK with the auth token created at server startup (or via `influxdb3 create token`)
  3. Verify intermediate proxies/gateways are not stripping the Authorization header

Example fix

// before
curl 'host/api/v3/query?db=mydb&q=select+1'
// after
curl -H 'Authorization: Bearer apiv3_xxxxxxxxxxxx' 'host/api/v3/query?db=mydb&q=select+1'
Defensive patterns

Strategy: validation

Validate before calling

function requireToken(cfg) {
  if (!cfg.token) throw new Error('auth token required: set Authorization: Bearer <token>');
}

Type guard

function hasToken(cfg) {
  return typeof cfg?.token === 'string' && cfg.token.length > 0;
}

Try / catch

try {
  return await api.call(req);
} catch (e) {
  if (e.status === 401 && String(e.message).includes('not authenticated')) {
    throw new ConfigError('missing auth token; configure Authorization header');
  }
  throw e;
}

Prevention

When it happens

Trigger: Calling any authenticated HTTP API (query, write, management) without an Authorization header; client has no token configured; token header dropped by an intermediate proxy.

Common situations: Fresh installations where auth is enabled but the client was never given a token; curl scripts that omit the header; load balancers stripping Authorization headers; SDK clients constructed without credentials.

Understand the failure class

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/193c61be5761693c. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_server/src/http.rs:400

    #[error("Cannot parse the timestamp: {0}")]
    ParsingTimestamp(#[from] chrono::ParseError),

    #[error("Timestamp is out of range")]
    TimestampOutOfRange,

    #[error("Current node mode does not use the processing engine")]
    NoProcessingEngine,

    #[error("invalid request: {0}")]
    InvalidRequest(String),

    #[error(transparent)]
    LegacyWriteParse(#[from] WriteParseError),
}

#[derive(Debug, Error)]
pub(crate) enum AuthenticationError {
    #[error("the request was not authenticated")]
    Unauthenticated,
    #[error(
        "Authorization header was malformed, the request was not in the form of 'Authorization: <auth-scheme> <token>', supported auth-schemes are Bearer, Token and Basic"
    )]
    MalformedRequest,
    #[error("requestor is forbidden from requested resource")]
    Forbidden,
    #[error("to str error: {0}")]
    ToStr(#[from] hyper::header::ToStrError),
}

impl IntoResponse for AuthenticationError {
    fn into_response(self) -> Response {
        let code = match self {
            Self::Unauthenticated => StatusCode::UNAUTHORIZED,
            Self::MalformedRequest => StatusCode::BAD_REQUEST,
            Self::Forbidden => StatusCode::FORBIDDEN,
            Self::ToStr(_) => StatusCode::INTERNAL_SERVER_ERROR,

View on GitHub (pinned to 06200ef96b)