tonhowtf/omniget · error

guest token ausente

Error message

guest token ausente

What it means

After the guest token request succeeds, the client parses the JSON and extracts the guest_token string field. If the field is missing or not a string, it errors with 'guest token ausente' — X replied but not with the expected token payload shape.

Solutions

  1. Log in with an account so the guest token path is not needed.
  2. Inspect the actual response body to see what X returned instead of guest_token.
  3. Retry from a different IP / after a delay if X is soft-challenging the client.
  4. Update the parsing code if X renamed/re-typed the field.

Example fix

// before
let tok = v.get("guest_token").and_then(|t| t.as_str()).ok_or_else(|| anyhow!("guest token ausente"))?;
// after
let tok = v.get("guest_token")
    .and_then(|t| t.as_str().map(str::to_owned).or_else(|| t.as_i64().map(|n| n.to_string())))
    .ok_or_else(|| anyhow!("guest token ausente: body={}", v))?
Defensive patterns

Strategy: try-catch

Type guard

fn extract_guest_token(v: &serde_json::Value) -> Option<String> {
    v.get("guest_token").and_then(|t| t.as_str().map(str::to_owned).or_else(|| t.as_i64().map(|n| n.to_string())))
}

Try / catch

match guest_op().await {
    Err(e) if e.to_string().contains("guest token ausente") => {
        log_response_snippet(); // capture what X actually returned
        fallback_to_authenticated_flow()
    }
    other => other,
}

Prevention

When it happens

Trigger: guest_token called via headers/gql_get when X's activation response JSON has no string 'guest_token' field — e.g. an HTML challenge/error page served with 200, or an API schema change.

Common situations: X serving a login/challenge page to suspicious IPs with HTTP 200; response is JSON but with different field casing/type; interception by a captive portal returning JSON error bodies.

Related errors


AI-assisted analysis of tonhowtf/omniget@8600b91f42 (2026-09-12). Data as JSON: /api/errors/55a4af8a542dfe98. Report an issue: GitHub.

Appendix: source

Thrown at src-tauri/omniget-core/src/core/tools/x/client.rs:214

        let resp = self
            .http
            .post("https://api.x.com/1.1/guest/activate.json")
            .header("Authorization", BEARER)
            .header("x-twitter-client-language", "en")
            .header("x-twitter-active-user", "yes")
            .send()
            .await?;
        if !resp.status().is_success() {
            return Err(anyhow!(
                "X nao entregou guest token: HTTP {}",
                resp.status()
            ));
        }
        let v: Value = resp.json().await?;
        let tok = v
            .get("guest_token")
            .and_then(|t| t.as_str())
            .ok_or_else(|| anyhow!("guest token ausente"))?
            .to_string();
        *g = Some((tok.clone(), Instant::now()));
        Ok(tok)
    }

    async fn tx_header(&self, method: &str, path: &str) -> Option<String> {
        if !self.authed() {
            return None;
        }
        let key = hash_str(self.cookie.as_deref().unwrap_or(""));
        let mut slot = TXID.lock().await;
        let fresh = match slot.as_ref() {
            Some((k, _, at)) => *k == key && at.elapsed() < Duration::from_secs(3600),
            None => false,
        };
        if !fresh {
            let gen = match TxIdGen::create(&self.http, self.cookie.as_deref()).await {
                Ok(g) => Some(g),

View on GitHub (pinned to 8600b91f42)