tiangolo/fastapi · error · HTTPException
X-Key header invalid
Error message
X-Key header invalid
What it means
Raised (400) by the verify_key dependency on GET /items/. The X-Key header must equal 'fake-super-secret-key'. Unlike verify_token, verify_key returns x_key (a usable dependency value), but the route does not consume it. verify_key runs after verify_token, so the token check must pass first.
Solutions
- Send X-Key: fake-super-secret-key together with a valid X-Token.
- Configure both headers in a shared auth helper on the client.
- Store both expected secrets in one config object to keep them in sync.
Example fix
// before GET /items/ X-Token: fake-super-secret-token // after GET /items/ X-Token: fake-super-secret-token X-Key: fake-super-secret-key
Defensive patterns
Strategy: validation
Validate before calling
import httpx
resp = httpx.get('http://localhost:8000/items/', headers={'X-Token': 'fake-super-secret-token', 'X-Key': 'fake-super-secret-key'}) Type guard
def is_valid_x_key(value: object) -> bool:
return isinstance(value, str) and value == 'fake-super-secret-key' Prevention
- Send X-Key whenever you send a valid X-Token.
- Pair both headers in a shared auth helper.
- Test that both headers are present before release.
When it happens
Trigger: GET /items/ with a correct X-Token but a missing/wrong X-Key header. Because verify_token precedes it, you only reach this line when the token is valid.
Common situations: Clients fix the token error and then hit the key error on the next attempt; or a client sends only one of the two required headers.
Related errors
- X-Key header invalid
- X-Token header invalid
- X-Token header invalid
- X-Token header invalid
- Invalid X-Token header
AI-assisted analysis of tiangolo/fastapi@3e8d1526d8 (2026-08-11).
Data as JSON: /api/errors/ef76ae82a3cbe001.
Report an issue: GitHub.
Appendix: source
Thrown at docs_src/dependencies/tutorial006_an_py310.py:15
from typing import Annotated
from fastapi import Depends, FastAPI, Header, HTTPException
app = FastAPI()
async def verify_token(x_token: Annotated[str, Header()]):
if x_token != "fake-super-secret-token":
raise HTTPException(status_code=400, detail="X-Token header invalid")
async def verify_key(x_key: Annotated[str, Header()]):
if x_key != "fake-super-secret-key":
raise HTTPException(status_code=400, detail="X-Key header invalid")
return x_key
@app.get("/items/", dependencies=[Depends(verify_token), Depends(verify_key)])
async def read_items():
return [{"item": "Foo"}, {"item": "Bar"}]
View on GitHub (pinned to 3e8d1526d8)