Atlas Knowledge Base
Dashboard
API Log - Authentication Messages

API Log - Authentication Messages


APIEngine issues a signed token when a user or integration signs in, and checks that token on every later request. The token is signed with the Token Secret from the APIEngine Settings page. A request whose token cannot be checked is refused.

What the caller receives (v96 and later)

ResponseMeaning
401 {"error":"Token expired."}The token was valid but its lifetime has passed
401 {"error":"Not Authorized."}No token was sent, the token was not signed with this server's Token Secret, it was altered or cut short, or it is a managed token that is inactive or expired

A browser opening an APIEngine page without a valid token is sent to the sign-in page instead.

v95 and earlier return 401 with the body "Not Authorized." for every refused token, including an expired one.

Log entries (v95 and earlier)

Invalid signature

The token could not be verified against this server's Token Secret. An expired but otherwise valid token is logged as "Token has expired" instead.

Common causes:

  • The Token Secret changed after the token was issued.
  • The token was issued by a different APIEngine server or farm that uses another Token Secret.
  • The token was cut short or altered in transit.

It marks a token this server no longer trusts, most often a stale one. It does not by itself indicate tampering.

Trying old authorization...

An informational entry. When the normal check of a token fails, APIEngine v95 and earlier retry it with an older validation method before refusing it. If the retry also fails, the request is refused. The two entries together are one rejected token.

What to do

An occasional rejected token is normal: a client reused an old token and needs to sign in again. If a client that should work is refused every time, confirm it signs in to the same server (or farm) it calls, and that every server in a farm has the same Token Secret. After changing the Token Secret, every client must sign in again.

More sign-in problems are on Troubleshooting.



Was this helpful?