influxdata/influxdb · error · AuthenticatorError

token has expired

Error message

token has expired {0}

What it means

AuthenticatorError::ExpiredToken is returned when the token exists in the catalog but its expiry timestamp has passed. The message includes the expiry details ({0}). The server treats the credential as no longer trustworthy and rejects the request.

Solutions

  1. Create a fresh token and update the credential store/secret
  2. Automate token rotation before expiry (watch the expiry timestamp in the error)
  3. Prefer non-expiring or long-lived tokens for long-running services

Example fix

// before
token = load_token() // expired
client = Client::new(url, None, false)?.with_auth_token(token)
// after: refresh if expired
if token.is_expired() { token = create_new_token() }
client = Client::new(url, None, false)?.with_auth_token(token)
Defensive patterns

Strategy: retry

Validate before calling

// parse expiry before use
if token_expiry <= Utc::now() { token = create_new_token()?; }

Try / catch

match result {
    Err(AuthenticatorError::ExpiredToken(exp)) => {
        warn!("token expired at {exp}; rotating");
        rotate_token_and_retry()
    }
    r => r?,
}

Prevention

When it happens

Trigger: A token with a finite TTL is used after its expiry; long-running processes holding a token reference across the expiry boundary; batch jobs started before token rotation.

Common situations: CI pipelines reusing cached tokens past their TTL; scheduled jobs with hardcoded tokens; environments where tokens were created with short expiries for testing.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/2ecd4391927d9bef. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/lib.rs:82

    Admin,
}

#[derive(Debug, Clone, thiserror::Error)]
pub enum ResourceAuthorizationError {
    #[error("unauthorized to perform requested action with the token")]
    Unauthorized,

    #[error("resource type not supported, {0}")]
    ResourceNotSupported(String),
}

#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
    /// Error for token that is present in the request but missing in the catalog
    #[error("token provided is not present in catalog")]
    InvalidToken,
    /// Error for token that has expired
    #[error("token has expired {0}")]
    ExpiredToken(String),
    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
    #[error("missing token to authenticate")]
    MissingToken,
    /// Error for invalid JWT (bad signature, malformed, etc.)
    #[error("invalid JWT")]
    InvalidJwt,
    /// Error for expired JWT
    #[error("JWT has expired")]
    ExpiredJwt,
}

impl From<AuthenticatorError> for IoxError {
    fn from(err: AuthenticatorError) -> Self {
        match err {
            AuthenticatorError::InvalidToken => IoxError::NoToken,
            AuthenticatorError::ExpiredToken(token_expiry_time) => {
                // there is no mapping to let the caller know about expired token in iox so

View on GitHub (pinned to 06200ef96b)