influxdata/influxdb · error · AuthenticatorError
token has expired
Error message
token has expired {0} What it means
AuthenticatorError::ExpiredToken is returned when the token exists in the catalog but its expiry timestamp has passed. The message includes the expiry details ({0}). The server treats the credential as no longer trustworthy and rejects the request.
Solutions
- Create a fresh token and update the credential store/secret
- Automate token rotation before expiry (watch the expiry timestamp in the error)
- Prefer non-expiring or long-lived tokens for long-running services
Example fix
// before
token = load_token() // expired
client = Client::new(url, None, false)?.with_auth_token(token)
// after: refresh if expired
if token.is_expired() { token = create_new_token() }
client = Client::new(url, None, false)?.with_auth_token(token) Defensive patterns
Strategy: retry
Validate before calling
// parse expiry before use
if token_expiry <= Utc::now() { token = create_new_token()?; } Try / catch
match result {
Err(AuthenticatorError::ExpiredToken(exp)) => {
warn!("token expired at {exp}; rotating");
rotate_token_and_retry()
}
r => r?,
} Prevention
- Track token expiry and rotate before it lapses
- Use long-lived tokens for unattended services
- Fail jobs fast with a clear 'expired token' check at startup
When it happens
Trigger: A token with a finite TTL is used after its expiry; long-running processes holding a token reference across the expiry boundary; batch jobs started before token rotation.
Common situations: CI pipelines reusing cached tokens past their TTL; scheduled jobs with hardcoded tokens; environments where tokens were created with short expiries for testing.
Related errors
- JWT has expired
- missing token to authenticate
- token provided is not present in catalog
- Authentication error
- duration not to overflow
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/2ecd4391927d9bef.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/lib.rs:82
Admin,
}
#[derive(Debug, Clone, thiserror::Error)]
pub enum ResourceAuthorizationError {
#[error("unauthorized to perform requested action with the token")]
Unauthorized,
#[error("resource type not supported, {0}")]
ResourceNotSupported(String),
}
#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
/// Error for token that is present in the request but missing in the catalog
#[error("token provided is not present in catalog")]
InvalidToken,
/// Error for token that has expired
#[error("token has expired {0}")]
ExpiredToken(String),
/// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
#[error("missing token to authenticate")]
MissingToken,
/// Error for invalid JWT (bad signature, malformed, etc.)
#[error("invalid JWT")]
InvalidJwt,
/// Error for expired JWT
#[error("JWT has expired")]
ExpiredJwt,
}
impl From<AuthenticatorError> for IoxError {
fn from(err: AuthenticatorError) -> Self {
match err {
AuthenticatorError::InvalidToken => IoxError::NoToken,
AuthenticatorError::ExpiredToken(token_expiry_time) => {
// there is no mapping to let the caller know about expired token in iox soView on GitHub (pinned to 06200ef96b)