toeverything/AFFiNE · error · SessionAccessTokenError
ACCESS_TOKEN_INVALID
ACCESS_TOKEN_INVALID
Error message
ACCESS_TOKEN_INVALID
What it means
SessionAccessTokenError with code ACCESS_TOKEN_INVALID is thrown during verify() when the token's embedded key id cannot be parsed (authSessionAccessTokenKeyId returns falsy), meaning the token is malformed or not a valid auth-session access token.
Solutions
- The access token is malformed or was tampered with — obtain a fresh token via the sign-in or refresh endpoint.
- Check the Authorization header format: 'Bearer <token>' with no extra whitespace or quotes.
- Ensure client and server share the same signing key/config; a key rotation invalidates old tokens.
Example fix
headers: { Authorization: `Bearer ${accessToken}` }
// If you still get ACCESS_TOKEN_INVALID, discard the stored token
// and sign in again. Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at packages/backend/server/src/core/auth/access-token.ts:69 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of toeverything/AFFiNE@b4c8548c09 (2026-08-18).
Data as JSON: /api/errors/24e53546b7e1d0a8.
Report an issue: GitHub.
Appendix: source
Thrown at packages/backend/server/src/core/auth/access-token.ts:69
const token = signAuthSessionAccessToken(
userId,
authSessionId,
key.id,
key.secret,
issuedAt,
expiresAtSeconds
);
if ((await this.keys.active()).id === key.id) {
return { token, expiresAt };
}
}
throw new AuthSessionTemporarilyUnavailable();
}
async verify(token: string): Promise<AuthSessionPrincipal> {
const keyId = authSessionAccessTokenKeyId(token);
if (!keyId) {
throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');
}
const key = await this.keys.verify(keyId);
if (!key) throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');
const verified = verifyAuthSessionAccessToken(
token,
keyId,
key.secret,
Math.floor(Date.now() / 1000)
);
if (verified.status !== 'valid') {
throw new SessionAccessTokenError(
verified.status === 'expired'
? 'ACCESS_TOKEN_EXPIRED'
: 'ACCESS_TOKEN_INVALID'
);
}
const { authSessionId, userId } = verified;
if (!authSessionId || !userId) {View on GitHub (pinned to b4c8548c09)