toeverything/AFFiNE · error · SessionAccessTokenError

ACCESS_TOKEN_INVALID

ACCESS_TOKEN_INVALID

Error message

ACCESS_TOKEN_INVALID

What it means

SessionAccessTokenError with code ACCESS_TOKEN_INVALID is thrown during verify() when the token's embedded key id cannot be parsed (authSessionAccessTokenKeyId returns falsy), meaning the token is malformed or not a valid auth-session access token.

Solutions

  1. The access token is malformed or was tampered with — obtain a fresh token via the sign-in or refresh endpoint.
  2. Check the Authorization header format: 'Bearer <token>' with no extra whitespace or quotes.
  3. Ensure client and server share the same signing key/config; a key rotation invalidates old tokens.

Example fix

headers: { Authorization: `Bearer ${accessToken}` }
// If you still get ACCESS_TOKEN_INVALID, discard the stored token
// and sign in again.
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/backend/server/src/core/auth/access-token.ts:69 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of toeverything/AFFiNE@b4c8548c09 (2026-08-18). Data as JSON: /api/errors/24e53546b7e1d0a8. Report an issue: GitHub.

Appendix: source

Thrown at packages/backend/server/src/core/auth/access-token.ts:69

      const token = signAuthSessionAccessToken(
        userId,
        authSessionId,
        key.id,
        key.secret,
        issuedAt,
        expiresAtSeconds
      );
      if ((await this.keys.active()).id === key.id) {
        return { token, expiresAt };
      }
    }
    throw new AuthSessionTemporarilyUnavailable();
  }

  async verify(token: string): Promise<AuthSessionPrincipal> {
    const keyId = authSessionAccessTokenKeyId(token);
    if (!keyId) {
      throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');
    }
    const key = await this.keys.verify(keyId);
    if (!key) throw new SessionAccessTokenError('ACCESS_TOKEN_INVALID');
    const verified = verifyAuthSessionAccessToken(
      token,
      keyId,
      key.secret,
      Math.floor(Date.now() / 1000)
    );
    if (verified.status !== 'valid') {
      throw new SessionAccessTokenError(
        verified.status === 'expired'
          ? 'ACCESS_TOKEN_EXPIRED'
          : 'ACCESS_TOKEN_INVALID'
      );
    }
    const { authSessionId, userId } = verified;
    if (!authSessionId || !userId) {

View on GitHub (pinned to b4c8548c09)