Skip to content

API key invalid

HTTP 401api_key_invalid

When the API answers 401 api_key_invalid, and how to fix it.

Version v1.1, updated

The type field of every api_key_invalid response links to this page.

On this page

The value after Bearer is not a valid API key. It may be incomplete, changed, or not a BIRP key at all.

At a glance

  • Status: 401 Unauthorized

  • Code: api_key_invalid

  • Retry: No. Fix the cause first: the same request gets the same answer.

Causes and fixes

Likely cause

How to fix it

A character is missing or extra, often a space, a line break or quotes around the key.

Copy the key again from your secrets manager, as one line without quotes.

The value is another secret, such as the key of another service.

Check which variable your code reads. Keep your key safe gives the format of a BIRP key.

The key was lost and typed again from memory or from a screenshot.

Create a new key in BIRP. A key is shown once and cannot be shown again.

Example

401 api_key_invalidJSON
{
  "code": "api_key_invalid",
  "detail": "The API key is malformed or unknown.",
  "instance": "/v1/categories",
  "request_id": "a1b2c3d4-0000-4000-8000-0000000000ee",
  "status": 401,
  "title": "API key invalid",
  "type": "https://birp.io/developers/errors/api_key_invalid"
}
  • first-key
  • keep-your-key-safe
  • api-key-revoked