tiangolo/fastapi · error · HTTPException

No Jessica token provided

Error message

No Jessica token provided

What it means

Raised (400) by get_query_token, a startup-time dependency passed to FastAPI() constructor (dependencies=) in the bigger-applications example. It validates that the 'token' query parameter equals 'jessica'. Because it is an app-level dependency, it runs for every route in the app, not just /items.

Solutions

  1. Append ?token=jessica to every request URL.
  2. Move this from a global dependency to specific routes if it should not apply app-wide.
  3. Remove the demo dependency entirely in real apps and use header/JWT auth.

Example fix

// before
GET /items/
// after
GET /items/?token=jessica
Defensive patterns

Strategy: validation

Validate before calling

import httpx
resp = httpx.get('http://localhost:8000/items/?token=jessica', headers={'X-Token': 'fake-super-secret-token'})

Type guard

def is_valid_query_token(value: object) -> bool:
    return isinstance(value, str) and value == 'jessica'

Prevention

When it happens

Trigger: Any request to the app that omits ?token=jessica or sends a different value. App-level dependencies fire before route matching details, so even unrelated routes are gated.

Common situations: Forgetting the query param entirely; sending ?token=Jessica (case mismatch); assuming the gate is route-local when it is actually global.

Related errors


AI-assisted analysis of tiangolo/fastapi@3e8d1526d8 (2026-08-11). Data as JSON: /api/errors/1365ee70a9f6ea2e. Report an issue: GitHub.

Appendix: source

Thrown at docs_src/bigger_applications/app_an_py310/dependencies.py:13

from typing import Annotated

from fastapi import Header, HTTPException


async def get_token_header(x_token: Annotated[str, Header()]):
    if x_token != "fake-super-secret-token":
        raise HTTPException(status_code=400, detail="X-Token header invalid")


async def get_query_token(token: str):
    if token != "jessica":
        raise HTTPException(status_code=400, detail="No Jessica token provided")

View on GitHub (pinned to 3e8d1526d8)