influxdata/influxdb · error · ResourceAuthorizationError

unauthorized to perform requested action with the token

Error message

unauthorized to perform requested action with the token

What it means

ResourceAuthorizationError::Unauthorized is returned by the influxdb3_authz authorizer when the authenticated principal's permissions do not cover the requested action on the resource. Unlike an authentication failure, the caller was identified but lacks entitlement. authorize_action converts any failed permission check into this error.

Solutions

  1. Issue a new token with the required permissions for the target resource
  2. Verify the token maps to the intended permission set in the catalog
  3. Use an admin credential for admin-only actions
  4. Check you are targeting the database the token was scoped to

Example fix

// before: read-only token used for a write
let client = Client::new(url, None, false)?.with_auth_token(&read_only_token);
// after: use a token with write permission on the database
let client = Client::new(url, None, false)?.with_auth_token(&write_token);
Defensive patterns

Strategy: try-catch

Type guard

fn is_unauthorized(err: &IoxError) -> bool {
    err.to_string().contains("unauthorized to perform requested action with the token")
}

Try / catch

match authorizer.authorize(...).await {
    Ok(()) => proceed(),
    Err(e) if matches!(e, ResourceAuthorizationError::Unauthorized) => {
        return status::Forbidden; // 403, not 401
    }
    Err(e) => return Err(e.into()),
}

Prevention

When it happens

Trigger: A token/user attempts a database or system action (read/write/create) whose required permission is absent from its permission set; e.g. a read-only token attempting a write, or a non-admin using an admin-only role action.

Common situations: Using a token scoped to one database against another; tokens created before a permission scheme change; attempting admin-only operations with a regular user.

Understand the failure class

Background: "You do not have permission" / 403 Forbidden errors: authenticated but not allowed — causes and fixes across open-source libraries — this error's family across 31 libraries.

Related errors


AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19). Data as JSON: /api/errors/3f9065672afe1830. Report an issue: GitHub.

Appendix: source

Thrown at influxdb3_authz/src/lib.rs:69

}

#[derive(Debug, Clone, Copy, PartialEq)]
pub enum AccessRequest {
    MaybeDatabase(Option<DbId>, DatabaseActions),
    Database(DbId, DatabaseActions),
    AnyDatabase(DatabaseActions),
    Token(TokenId, CrudActions),
    System(SystemResourceIdentifier, SystemActions),
    User(role::UserAction),
    Role(role::RoleAction),
    AdminToken(role::AdminTokenAction),
    ResourceToken(role::TokenAction),
    Admin,
}

#[derive(Debug, Clone, thiserror::Error)]
pub enum ResourceAuthorizationError {
    #[error("unauthorized to perform requested action with the token")]
    Unauthorized,

    #[error("resource type not supported, {0}")]
    ResourceNotSupported(String),
}

#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
    /// Error for token that is present in the request but missing in the catalog
    #[error("token provided is not present in catalog")]
    InvalidToken,
    /// Error for token that has expired
    #[error("token has expired {0}")]
    ExpiredToken(String),
    /// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
    #[error("missing token to authenticate")]
    MissingToken,
    /// Error for invalid JWT (bad signature, malformed, etc.)

View on GitHub (pinned to 06200ef96b)