moeru-ai/airi · error · Error

Failed to create token

Error message

Failed to create token: ${JSON.stringify(response) || 'Unknown error'}

What it means

The Aliyun NLS token endpoint answered, but the response lacked Token.Id, so the code treats the whole envelope as an error and embeds it via JSON.stringify — the thrown message therefore contains the server's own RequestId, Code, and Message. This is a server-side rejection of the credentials or the account, not a network failure.

Solutions

  1. Read the Code and Message inside the thrown JSON — e.g. InvalidAccessKeyId.NotFound, SignatureDoesNotMatch, NoPermission
  2. Attach an NLS access policy to the RAM user in the Alibaba Cloud console
  3. Re-copy AK, SK, and appKey from the console into provider settings
  4. Check the Alibaba Cloud account for overdue payments

Example fix

// before
const { token } = await createAliyunToken(accessKeyId, accessKeySecret)
// throws: 'Failed to create token: {RequestId, Code: NoPermission, Message}'

// after
try {
  const { token } = await createAliyunToken(accessKeyId, accessKeySecret)
}
catch (err) {
  const detail = JSON.parse(err.message.replace(/^Failed to create token: /, ''))
  if (detail.Code === 'NoPermission')
    throw new Error('Attach an NLS access policy to this RAM user')
}
Defensive patterns

Strategy: try-catch

Try / catch

try {
  await createAliyunToken(accessKeyId, accessKeySecret)
}
catch (err) {
  // The message is JSON.stringify of the server envelope — parse it back
  // to surface Code/Message instead of showing a raw dump.
  const envelope = JSON.parse(err.message.replace(/^Failed to create token: /, ''))
  showCredentialError(envelope.Code, envelope.Message)
}

Prevention

When it happens

Trigger: AccessKey pair valid but the RAM user lacks NLS permissions; AK/SK incorrect or disabled; appKey not created in this NLS project or region; account in arrears.

Common situations: RAM user created for the app without attaching an NLS access policy; key rotated but provider settings still hold the old one; using keys from a different Alibaba Cloud account than the NLS project.

Related errors


AI-assisted analysis of moeru-ai/airi@677329427f (2026-08-18). Data as JSON: /api/errors/daf8ba5f816847d3. Report an issue: GitHub.

Appendix: source

Thrown at packages/stage-ui/src/libs/providers/providers/aliyun-nls/token.ts:134

export async function createToken(accessKeyId: string, accessKeySecret: string, options?: CreateTokenOptions): Promise<{ token: string, expiresAt: number }> {
  const request = await buildCreateTokenRequest(accessKeyId, accessKeySecret, options)
  const response = await ofetch<{
    NlsRequestId: string
    RequestId: string
    ErrMsg: string
    Token: { ExpireTime: number, Id: string, UserId: string }
  } | {
    RequestId: string
    Message: string
    Code: string
  }>(request.url, { method: 'POST' })

  if ('Token' in response && typeof response.Token === 'object' && 'Id' in response.Token) {
    return { token: response.Token.Id, expiresAt: response.Token.ExpireTime * 1000 }
  }

  throw new Error(`Failed to create token: ${JSON.stringify(response) || 'Unknown error'}`)
}

View on GitHub (pinned to 677329427f)