tiangolo/fastapi · error · HTTPException
No Jessica token provided
Error message
No Jessica token provided
What it means
Raised (400) by get_query_token, a startup-time dependency passed to FastAPI() constructor (dependencies=) in the bigger-applications example. It validates that the 'token' query parameter equals 'jessica'. Because it is an app-level dependency, it runs for every route in the app, not just /items.
Solutions
- Append ?token=jessica to every request URL.
- Move this from a global dependency to specific routes if it should not apply app-wide.
- Remove the demo dependency entirely in real apps and use header/JWT auth.
Example fix
// before GET /items/ // after GET /items/?token=jessica
Defensive patterns
Strategy: validation
Validate before calling
import httpx
resp = httpx.get('http://localhost:8000/items/?token=jessica', headers={'X-Token': 'fake-super-secret-token'}) Type guard
def is_valid_query_token(value: object) -> bool:
return isinstance(value, str) and value == 'jessica' Prevention
- Remember this is an app-level dependency: it applies to every route.
- Append ?token=jessica via a base-URL helper.
- Remove the demo dependency before shipping.
When it happens
Trigger: Any request to the app that omits ?token=jessica or sends a different value. App-level dependencies fire before route matching details, so even unrelated routes are gated.
Common situations: Forgetting the query param entirely; sending ?token=Jessica (case mismatch); assuming the gate is route-local when it is actually global.
Related errors
- X-Token header invalid
- X-Key header invalid
- X-Key header invalid
- X-Token header invalid
- X-Token header invalid
AI-assisted analysis of tiangolo/fastapi@3e8d1526d8 (2026-08-11).
Data as JSON: /api/errors/1365ee70a9f6ea2e.
Report an issue: GitHub.
Appendix: source
Thrown at docs_src/bigger_applications/app_an_py310/dependencies.py:13
from typing import Annotated
from fastapi import Header, HTTPException
async def get_token_header(x_token: Annotated[str, Header()]):
if x_token != "fake-super-secret-token":
raise HTTPException(status_code=400, detail="X-Token header invalid")
async def get_query_token(token: str):
if token != "jessica":
raise HTTPException(status_code=400, detail="No Jessica token provided")
View on GitHub (pinned to 3e8d1526d8)