moeru-ai/airi · error · Error
Failed to create token
Error message
Failed to create token: ${JSON.stringify(response) || 'Unknown error'} What it means
The Aliyun NLS token endpoint answered, but the response lacked Token.Id, so the code treats the whole envelope as an error and embeds it via JSON.stringify — the thrown message therefore contains the server's own RequestId, Code, and Message. This is a server-side rejection of the credentials or the account, not a network failure.
Solutions
- Read the Code and Message inside the thrown JSON — e.g. InvalidAccessKeyId.NotFound, SignatureDoesNotMatch, NoPermission
- Attach an NLS access policy to the RAM user in the Alibaba Cloud console
- Re-copy AK, SK, and appKey from the console into provider settings
- Check the Alibaba Cloud account for overdue payments
Example fix
// before
const { token } = await createAliyunToken(accessKeyId, accessKeySecret)
// throws: 'Failed to create token: {RequestId, Code: NoPermission, Message}'
// after
try {
const { token } = await createAliyunToken(accessKeyId, accessKeySecret)
}
catch (err) {
const detail = JSON.parse(err.message.replace(/^Failed to create token: /, ''))
if (detail.Code === 'NoPermission')
throw new Error('Attach an NLS access policy to this RAM user')
} Defensive patterns
Strategy: try-catch
Try / catch
try {
await createAliyunToken(accessKeyId, accessKeySecret)
}
catch (err) {
// The message is JSON.stringify of the server envelope — parse it back
// to surface Code/Message instead of showing a raw dump.
const envelope = JSON.parse(err.message.replace(/^Failed to create token: /, ''))
showCredentialError(envelope.Code, envelope.Message)
} Prevention
- Attach the NLS policy to the RAM user before shipping keys
- Smoke-test the AK/SK with the Aliyun CLI on first configuration
- Treat any non-Token envelope as a config problem and stop retrying
When it happens
Trigger: AccessKey pair valid but the RAM user lacks NLS permissions; AK/SK incorrect or disabled; appKey not created in this NLS project or region; account in arrears.
Common situations: RAM user created for the app without attaching an NLS access policy; key rotated but provider settings still hold the old one; using keys from a different Alibaba Cloud account than the NLS project.
Related errors
- Aliyun NLS credentials are incomplete.
- 1. Microphone permission not granted - browser should…
- Aliyun NLS returned a non-streaming result unexpectedly.
- Cannot declare permissions for unknown plugin
- Cannot grant permissions to unknown plugin
AI-assisted analysis of moeru-ai/airi@677329427f (2026-08-18).
Data as JSON: /api/errors/daf8ba5f816847d3.
Report an issue: GitHub.
Appendix: source
Thrown at packages/stage-ui/src/libs/providers/providers/aliyun-nls/token.ts:134
export async function createToken(accessKeyId: string, accessKeySecret: string, options?: CreateTokenOptions): Promise<{ token: string, expiresAt: number }> {
const request = await buildCreateTokenRequest(accessKeyId, accessKeySecret, options)
const response = await ofetch<{
NlsRequestId: string
RequestId: string
ErrMsg: string
Token: { ExpireTime: number, Id: string, UserId: string }
} | {
RequestId: string
Message: string
Code: string
}>(request.url, { method: 'POST' })
if ('Token' in response && typeof response.Token === 'object' && 'Id' in response.Token) {
return { token: response.Token.Id, expiresAt: response.Token.ExpireTime * 1000 }
}
throw new Error(`Failed to create token: ${JSON.stringify(response) || 'Unknown error'}`)
}
View on GitHub (pinned to 677329427f)