upstash/context7 · error · SessionRejectedError
Session was rejected by the server
Error message
Session was rejected by the server
What it means
SessionRejectedError is thrown by fetchWhoami when the dashboard /api/dashboard/whoami endpoint responds with HTTP 401. It means the stored access token is present but the server rejected it, so the CLI cannot identify the current user. It is a distinct class so the whoami command can print a targeted 'log in again' message instead of a generic network failure.
Solutions
- Run 'ctx7 logout' then 'ctx7 login' to obtain a fresh access token.
- Verify you are pointing at the intended base URL (a stale CONTEXT7 base URL config can invalidate the token).
- If re-login fails repeatedly, delete stored credentials/config and authenticate from scratch.
Example fix
// before (stale token in shell env) export CONTEXT7_API_TOKEN=old-expired-token ctx7 whoami // after (re-authenticate) ctx7 logout ctx7 login ctx7 whoami
Defensive patterns
Strategy: try-catch
Validate before calling
// Can't validate token validity locally, but ensure it exists and looks like a token before calling:
if (!accessToken || accessToken.length < 10) {
throw new Error('No stored access token; run login first');
} Type guard
function isSessionRejected(e: unknown): e is SessionRejectedError {
return e instanceof SessionRejectedError;
} Try / catch
try {
const whoami = await fetchWhoami(token);
} catch (e) {
if (e instanceof SessionRejectedError) {
await reauthenticate(); // logout + login
} else {
console.error('Transient failure, retry later');
}
} Prevention
- Re-authenticate proactively when tokens near expiry.
- Keep base-URL config consistent between login and subsequent calls.
- Handle 401 centrally by clearing stored credentials and prompting re-login.
When it happens
Trigger: fetchWhoami(accessToken) is called (via whoami) and the response from `${getBaseUrl()}/api/dashboard/whoami` with `Authorization: Bearer ${accessToken}` returns status 401.
Common situations: The stored auth token has expired or been revoked server-side; the user logged out or rotated keys in another session; token was minted for a different environment/base URL; system clock skew invalidated the token.
Related errors
- -32001
- API key is required. Pass it in the config or set…
- API key should start with
- authentication_error
- Authentication is required. Pass apiKey or authToken, or…
AI-assisted analysis of upstash/context7@4416fb855b (2026-09-16).
Data as JSON: /api/errors/204b4e6fc76ef56a.
Report an issue: GitHub.
Appendix: source
Thrown at packages/cli/src/commands/auth.ts:272
interface WhoamiResponse {
success: boolean;
name: string | null;
email: string | null;
teamspace: { id: string; name: string } | null;
}
class SessionRejectedError extends Error {}
async function fetchWhoami(accessToken: string): Promise<WhoamiResponse> {
const response = await fetch(`${getBaseUrl()}/api/dashboard/whoami`, {
headers: {
Authorization: `Bearer ${accessToken}`,
},
});
if (response.status === 401) {
throw new SessionRejectedError("Session was rejected by the server");
}
if (!response.ok) {
throw new Error("Failed to fetch user info");
}
return (await response.json()) as WhoamiResponse;
}
View on GitHub (pinned to 4416fb855b)