tiangolo/fastapi · error · HTTPException

X-Key header invalid

Error message

X-Key header invalid

What it means

Legacy-style variant of error 15: verify_key on GET /items/ raises 400 when X-Key != 'fake-super-secret-key'. Runs after verify_token, so it fires only when the token is already valid.

Solutions

  1. Send X-Key: fake-super-secret-key alongside a valid X-Token.
  2. Keep both headers in one auth helper.
  3. Move to the Annotated variant.

Example fix

// before
GET /items/   X-Token: fake-super-secret-token
// after
GET /items/   X-Token: fake-super-secret-token   X-Key: fake-super-secret-key
Defensive patterns

Strategy: validation

Validate before calling

import httpx
resp = httpx.get('http://localhost:8000/items/', headers={'X-Token': 'fake-super-secret-token', 'X-Key': 'fake-super-secret-key'})

Type guard

def is_valid_x_key(value: object) -> bool:
    return isinstance(value, str) and value == 'fake-super-secret-key'

Prevention

When it happens

Trigger: GET /items/ with valid X-Token but wrong/missing X-Key.

Common situations: Fixing the token and immediately hitting the key gate; sending only one of the two headers.

Related errors


AI-assisted analysis of tiangolo/fastapi@3e8d1526d8 (2026-08-11). Data as JSON: /api/errors/506fb6c7711b1170. Report an issue: GitHub.

Appendix: source

Thrown at docs_src/dependencies/tutorial006_py310.py:13

from fastapi import Depends, FastAPI, Header, HTTPException

app = FastAPI()


async def verify_token(x_token: str = Header()):
    if x_token != "fake-super-secret-token":
        raise HTTPException(status_code=400, detail="X-Token header invalid")


async def verify_key(x_key: str = Header()):
    if x_key != "fake-super-secret-key":
        raise HTTPException(status_code=400, detail="X-Key header invalid")
    return x_key


@app.get("/items/", dependencies=[Depends(verify_token), Depends(verify_key)])
async def read_items():
    return [{"item": "Foo"}, {"item": "Bar"}]

View on GitHub (pinned to 3e8d1526d8)