influxdata/influxdb · error · AuthenticatorError

token provided is not present in catalog

Error message

token provided is not present in catalog

What it means

AuthenticatorError::InvalidToken indicates that a bearer token was supplied in the request but no matching token exists in the server's catalog. The server refuses to authenticate the request because the credential is unknown. It is an authentication (who-are-you) failure, not an authorization failure.

Solutions

  1. Generate/re-issue a valid token with `influxdb3 create token` and update the client
  2. Verify the token string is complete and unmodified (no whitespace/truncation)
  3. Confirm the client targets the same instance the token was created on

Example fix

// before
export INFLUXDB3_AUTH_TOKEN=old-revoked-token
// after
export INFLUXDB3_AUTH_TOKEN=$(influxdb3 create token --permission ... )
Defensive patterns

Strategy: validation

Validate before calling

// check the token exists before calling the API
assert!(!token.is_empty(), "no auth token configured");
// verify via a cheap authenticated endpoint, e.g. GET /health with auth

Try / catch

// map to 401 and re-provision
def call_with_auth(f):
    try: return f()
    except ApiError as e:
        if 'token provided is not present in catalog' in str(e):
            token = provision_new_token(); return f()  # retry once with fresh token
        raise

Prevention

When it happens

Trigger: Sending an Authorization: Bearer <token> whose value was deleted, rotated, or belongs to a different InfluxDB instance; typoes or truncation when copying the token.

Common situations: Tokens regenerated without updating client config; pointing a client at a different environment (staging vs prod) that has different tokens; stale tokens in env vars or CI secrets after a revoke.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/3ee39a66d13f10ed. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/lib.rs:79

    Role(role::RoleAction),
    AdminToken(role::AdminTokenAction),
    ResourceToken(role::TokenAction),
    Admin,
}

#[derive(Debug, Clone, thiserror::Error)]
pub enum ResourceAuthorizationError {
    #[error("unauthorized to perform requested action with the token")]
    Unauthorized,

    #[error("resource type not supported, {0}")]
    ResourceNotSupported(String),
}

#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
    /// Error for token that is present in the request but missing in the catalog
    #[error("token provided is not present in catalog")]
    InvalidToken,
    /// Error for token that has expired
    #[error("token has expired {0}")]
    ExpiredToken(String),
    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
    #[error("missing token to authenticate")]
    MissingToken,
    /// Error for invalid JWT (bad signature, malformed, etc.)
    #[error("invalid JWT")]
    InvalidJwt,
    /// Error for expired JWT
    #[error("JWT has expired")]
    ExpiredJwt,
}

impl From<AuthenticatorError> for IoxError {
    fn from(err: AuthenticatorError) -> Self {
        match err {

View on GitHub (pinned to 06200ef96b)