influxdata/influxdb · error · ResourceAuthorizationError
unauthorized to perform requested action with the token
Error message
unauthorized to perform requested action with the token
What it means
ResourceAuthorizationError::Unauthorized is returned by the influxdb3_authz authorizer when the authenticated principal's permissions do not cover the requested action on the resource. Unlike an authentication failure, the caller was identified but lacks entitlement. authorize_action converts any failed permission check into this error.
Solutions
- Issue a new token with the required permissions for the target resource
- Verify the token maps to the intended permission set in the catalog
- Use an admin credential for admin-only actions
- Check you are targeting the database the token was scoped to
Example fix
// before: read-only token used for a write let client = Client::new(url, None, false)?.with_auth_token(&read_only_token); // after: use a token with write permission on the database let client = Client::new(url, None, false)?.with_auth_token(&write_token);
Defensive patterns
Strategy: try-catch
Type guard
fn is_unauthorized(err: &IoxError) -> bool {
err.to_string().contains("unauthorized to perform requested action with the token")
} Try / catch
match authorizer.authorize(...).await {
Ok(()) => proceed(),
Err(e) if matches!(e, ResourceAuthorizationError::Unauthorized) => {
return status::Forbidden; // 403, not 401
}
Err(e) => return Err(e.into()),
} Prevention
- Issue tokens with the exact permissions the workload needs
- Audit permission sets after auth scheme changes
- Use admin credentials only for admin operations
- Keep a test that exercises each token's permitted actions
When it happens
Trigger: A token/user attempts a database or system action (read/write/create) whose required permission is absent from its permission set; e.g. a read-only token attempting a write, or a non-admin using an admin-only role action.
Common situations: Using a token scoped to one database against another; tokens created before a permission scheme change; attempting admin-only operations with a regular user.
Understand the failure class
Background: "You do not have permission" / 403 Forbidden errors: authenticated but not allowed — causes and fixes across open-source libraries — this error's family across 31 libraries.
- Authentication and authorization failures — expired tokens, bad credentials, and missing scopes.
Related errors
- Authorization error
- duration not to overflow
- Failed to put initial table index conversion marker to…
- from hex error
- missing token to authenticate
AI-assisted analysis of influxdata/influxdb@06200ef96b (2026-09-19).
Data as JSON: /api/errors/3f9065672afe1830.
Report an issue: GitHub.
Appendix: source
Thrown at influxdb3_authz/src/lib.rs:69
}
#[derive(Debug, Clone, Copy, PartialEq)]
pub enum AccessRequest {
MaybeDatabase(Option<DbId>, DatabaseActions),
Database(DbId, DatabaseActions),
AnyDatabase(DatabaseActions),
Token(TokenId, CrudActions),
System(SystemResourceIdentifier, SystemActions),
User(role::UserAction),
Role(role::RoleAction),
AdminToken(role::AdminTokenAction),
ResourceToken(role::TokenAction),
Admin,
}
#[derive(Debug, Clone, thiserror::Error)]
pub enum ResourceAuthorizationError {
#[error("unauthorized to perform requested action with the token")]
Unauthorized,
#[error("resource type not supported, {0}")]
ResourceNotSupported(String),
}
#[derive(Debug, thiserror::Error)]
pub enum AuthenticatorError {
/// Error for token that is present in the request but missing in the catalog
#[error("token provided is not present in catalog")]
InvalidToken,
/// Error for token that has expired
#[error("token has expired {0}")]
ExpiredToken(String),
/// Error for missing token (this should really be handled at the HTTP/Grpc API layer itself)
#[error("missing token to authenticate")]
MissingToken,
/// Error for invalid JWT (bad signature, malformed, etc.)View on GitHub (pinned to 06200ef96b)