jdx/mise · error
brew-cask: requested token
Error message
brew-cask: requested token '{requested_token}' does not match API token '{}' What it means
`validate_cask_identity` verifies that the token the user requested matches the token reported by the fetched Homebrew API cask JSON, allowing trusted aliases listed in the cask's `aliases`/`old_tokens`. A mismatch means the API returned metadata for a different cask than asked for — possibly a redirect, renamed cask, or spoofed/incorrect mapping — so the fetch is aborted rather than installing the wrong software.
Solutions
- Use the exact API token reported in the error message as the requested token
- Refresh cask metadata/caches so renamed tokens resolve to their new names
- If the old name should still work, add it to the cask's `aliases`/`old_tokens` in the tap
Example fix
// before brew-cask install "old-cask-name" // after brew-cask install "new-cask-name"
Defensive patterns
Strategy: validation
Validate before calling
// After fetching cask JSON, confirm the token identity before installing
if api_json["token"] != requested_token
&& !api_json["aliases"].as_array().map_or(false, |a| a.iter().any(|v| v == requested_token))
&& !api_json["old_tokens"].as_array().map_or(false, |a| a.iter().any(|v| v == requested_token)) {
eprintln!("requested token {} does not match API token {}", requested_token, api_json["token"]);
} Prevention
- Use the exact token returned by the API, not a guessed shorthand
- Refresh cached cask metadata after upstream renames
- Verify alias names exist before scripting installs
When it happens
Trigger: fetch_cask or fetch_cask_url fetches cask JSON whose `token` field differs from `requested_token` and the requested token is not in the cask's `aliases` or `old_tokens` lists.
Common situations: A cask was renamed upstream while a cached or pinned token was used; a tap's token-to-JSON mapping is wrong; a shorthand/alias was guessed by the user that is not an official alias.
Related errors
- brew-cask: invalid
- app target is outside an allowed Applications directory
- artifact target has changed
- binary target is not an owned Caskroom symlink
- brew-cask: : cask metadata has no sha256
AI-assisted analysis of jdx/mise@533346cc37 (2026-09-17).
Data as JSON: /api/errors/d69ae6f6685126dc.
Report an issue: GitHub.
Appendix: source
Thrown at src/system/packages/brew/cask/fetch.rs:122
validate_cask_identity(&cask, requested_token, official_api)?;
Ok(cask)
}
pub(super) fn validate_cask_identity(
cask: &Cask,
requested_token: &str,
official_api: bool,
) -> Result<()> {
validate_cask_path_component("API token", &cask.token)?;
validate_cask_path_component("version", &cask.version)?;
let trusted_alias = official_api
&& cask
.aliases
.iter()
.chain(&cask.old_tokens)
.any(|alias| alias == requested_token);
if cask.token != requested_token && !trusted_alias {
bail!(
"brew-cask: requested token '{requested_token}' does not match API token '{}'",
cask.token
);
}
Ok(())
}
pub(super) fn validate_cask_path_component(kind: &str, value: &str) -> Result<()> {
let mut components = Path::new(value).components();
let valid = !value.is_empty()
&& !value.contains('\0')
&& !value.contains('\\')
&& matches!(components.next(), Some(Component::Normal(_)))
&& components.next().is_none()
&& value != ".metadata"
&& !value.starts_with(".mise-");
if !valid {
bail!("brew-cask: invalid {kind} '{value}'");View on GitHub (pinned to 533346cc37)